Polished Phishing Bypasses Trust Controls at Scale

Phishing no longer has to look like phishing to work. This campaign used enterprise-style lures and legitimate email services to make token-harvesting messages look like internal compliance traffic, which is the kind of message users are trained to trust and filters are less likely to block. Microsoft says the campaign ran from April 14 to 16, 2026 and targeted more than 35,000 users at over 13,000 organizations in 26 countries. The heaviest targeting hit healthcare and life sciences, financial services, professional services, and technology, with 92% of targets in the U.S. The forward risk is delivery, not just content. If attackers can borrow reputable email infrastructure and mimic internal process language, reputation-based defenses and blocklists lose much of their value against token theft campaigns.

Part of the PlainSec briefing for 2026-05-06

Sources