Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

blog.checkpoint.com/email-sec…

Between 25 June and the second week of July 2026, researchers identified more than 200 phishing emails that targeted users at approximately 120 organizations across multiple industries and countries. The messages impersonated Microsoft Teams task notifications from HR departments.

Instead of directing victims to fake login pages, the campaign sent recipients to legitimate Microsoft sign-in pages and then prompted them to grant permissions to an attacker-controlled application. This approach abuses Microsoft’s own trusted authentication infrastructure, allowing the attacks to bypass many of the visual and technical warning signs that users have been trained to spot.

Edward Kiledjian @ekiledjian