Attackers now using real Microsoft sign-in screen for phishing — Here’s What Happened

Attackers now using real Microsoft sign-in screen for phishing — Here’s What Happened

Attackers used real Microsoft sign-in pages to trick workers into approving harmful apps. Here’s how the phishing scam works and what you can do to protect your Microsoft account today.

What Happened?

According to Cybernews, Check Point researchers uncovered a phishing campaign that used genuine Microsoft sign-in pages instead of fake login websites.

The campaign ran from June 25 through the second week of July 2026. Researchers found more than 200 emails targeting about 120 organizations worldwide.

The emails looked like Microsoft Teams task alerts from a company’s HR department. They mentioned payroll, compensation, benefits, and four overdue employee tasks.

Clicking a link opened the real login.microsoftonline.com website. However, the next screen asked the user to approve permissions for an attacker-controlled app.

Check Point said this specific campaign is no longer active. However, the same phishing method could be used in future attacks.

Phishing messages can look more convincing when criminals know your name, employer, or email address. Those details may come from earlier data breaches.

Many people do not know their information was leaked until a believable message arrives. Automatic monitoring can help you notice that risk sooner.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Targeted and What Could Attackers Access?

Check Point identified more than 200 phishing emails sent to users at approximately 120 organizations.

Among organizations with known locations, 98.3% were in North America. Manufacturing, legal services, nonprofits, government, and healthcare were among the targeted sectors.

Researchers did not say how many people approved the app. They also did not confirm that any specific personal or company data was taken.

However, an approved app could access information based on the permissions shown. That could include email, files, Teams chats, SharePoint, OneDrive, and calendar details.

The app might also send email from the user’s mailbox. This could help criminals target coworkers using an address they already trust.

Check if your data is safe from scammers

Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.

Check my safety

How the Microsoft Sign-In Phishing Scam Worked

The phishing scam used a method called consent phishing. This means criminals trick you into giving a harmful app permission to access your information.

First, the user received a fake Teams notification that appeared to come from HR. The message created urgency with overdue tasks and payroll information.

Next, every button led through the same redirect and opened Microsoft’s genuine sign-in page.

After signing in, the user saw a permission request. It could include options such as “Approve permissions” or “Accept on behalf of your organization.”

If the user approved the request, Microsoft sent an authorization code to infrastructure controlled by the attackers.

That code could let the harmful app access Microsoft 365 services without stealing the user’s password.

Microsoft calls this consent phishing. The attacker targets the permissions you can grant instead of trying to steal your login details.