Microsoft phishing exploits trusted login flow

Cybercriminals are changing how phishing attacks work, making them much harder to detect. A recent Microsoft phishing campaign no longer relies on fake login pages. Instead, attackers use Microsoft's legitimate authentication process, allowing malicious emails to blend into normal business workflows and bypass many of the warning signs employees have been trained to spot.
Researchers identified more than 200 phishing emails sent between June 25 and the second week of July, targeting users across around 120 organizations worldwide. The emails impersonated Microsoft Teams task notifications from HR and encouraged recipients to sign in through a genuine Microsoft login page. Once authenticated, users were asked to approve permissions for an attacker-controlled application through an OAuth phishing technique.
How the trusted login exploit works
Unlike traditional phishing campaigns, this trusted login exploit takes users to the legitimate page. After signing in, victims are presented with a permissions screen requesting access for an application. If approved, Microsoft redirects the authentication token to attacker-controlled infrastructure, allowing access based on the permissions granted.
According to the findings, the technique has evolved from targeted attacks into a service that can be rented, making it more accessible to cybercriminals. Researchers noted that attackers are no longer forging Microsoft's front door but instead abusing its trusted authentication process.
Microsoft 365 security faces new enterprise cyber threats
Depending on the permissions granted, attackers can access email, Teams conversations, SharePoint sites, OneDrive files, and calendars across a victim's Microsoft 365 security environment. Such access can also be used to launch follow-on business email compromise attacks from trusted internal accounts, increasing the impact of broader enterprise cyber threats.
Most of the identified campaigns targeted organizations in North America, while manufacturing, legal services, nonprofits, government, and healthcare were among the most affected sectors.
Read More:
5Tattva Accelerates Enterprise Engagement Across CIO500 Event Series
Matrix and Yotta Partnership takes surveillance to cloud
Tenable takes exposure management toward autonomous security






