Threats · 132 days ago
Phishing no longer has to look like phishing to work. This campaign used enterprise-style lures and legitimate email services to make token-harvesting messages look like internal compliance traffic, which is the kind of message users are trained to trust and filters are less likely to block.
Microsoft says the campaign ran from April 14 to 16, 2026 and targeted more than 35,000 users at over 13,000 organizations in 26 countries. The heaviest targeting hit healthcare and life sciences, financial services, professional services, and technology, with 92% of targets in the U.S.
The forward risk is delivery, not just content. If attackers can borrow reputable email infrastructure and mimic internal process language, reputation-based defenses and blocklists lose much of their value against token theft campaigns.
4 sources covering this story
Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails
Microsoft researchers warn of a large-scale phishing campaign using fake compliance emails to steal credentials, targeting 35,000 users across 13,000 organizations worldwide
Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations
The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM.
Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
Microsoft disclosed a credential theft campaign targeting 35,000+ users at 13,000+ organizations across 26 countries.
Phishers have been using fake workplace compliance notices to try to trick Microsoft account owners into signing in via a fake sign-in page.
Part of the PlainSec briefing for 2026-05-06