Hackers Use Real Microsoft Login Pages in Phishing Scam — Here’s What Happened

Hackers Use Real Microsoft Login Pages in Phishing Scam — Here’s What Happened

Hackers used real Microsoft login pages to trick workers into approving a harmful app. Here’s how to spot suspicious permission requests and better protect your Microsoft 365 data from hackers.

What Happened?

According to TechRadar, attackers used legitimate Microsoft sign-in pages in a phishing campaign active from June 25 through mid-July 2026.

Check Point found more than 200 phishing emails targeting users across about 120 organizations worldwide. The messages looked like Microsoft Teams or Planner notifications from HR.

They mentioned payroll, benefits, and overdue tasks to create urgency. However, the email links opened a real Microsoft login page.

After signing in, users saw a request to approve permissions for an attacker-controlled app. Anyone who approved could give the app access to workplace data.

Check Point says the campaign is no longer active. However, criminals can reuse the same method in future phishing attacks.

Access to email and files can reveal personal details that support later phishing attempts. Many people also have information circulating from earlier breaches without realizing it.

If you are unsure whether your information was leaked elsewhere, automatic monitoring can help. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Targeted and What Could Hackers Access?

The campaign targeted users at organizations worldwide. Among customers whose locations were identified, 98.3% were in North America.

Manufacturing, professional services, nonprofits, government agencies, and healthcare organizations were among the leading targets.

Check Point did not say how many recipients approved the app permissions. Therefore, the number of users who granted access remains unclear.

The possible access depended on what each user approved. It could include email, files, Teams chats, SharePoint content, OneDrive storage, calendars, and meeting details.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

How Hackers Used Microsoft’s Real Sign-In System

The attack began with an email that looked like a Microsoft Teams or Planner notice. A link directed the recipient to Microsoft’s real login website.

That address belonged to Microsoft, so the usual warning signs were missing. The page then displayed an app permission request.

The page used Microsoft’s OAuth system, which lets apps request account access without receiving your password.

If the user approved the request, Microsoft sent an authorization code to an internet address controlled by the attackers.

The attackers exchanged that code for a token. A token is a digital pass that lets an approved app use allowed parts of your account.

This method is called consent phishing. It tricks you into granting a harmful app permission to access your data without stealing your password.