Microsoft Consent Pages Let Phishing Bypass Fake-Login Checks
The weakness is the trust model, not the login page. If the page is real Microsoft, the usual advice to spot a fake sign-in screen stops working, and a user can hand over lasting access by approving an OAuth request instead of typing a password into a phony site.
Check Point says it saw 200+ phishing emails from June 25 into the second week of July, aimed at around 120 organizations. The lures used Microsoft Planner branding, internal-looking sender details, and multiple buttons that all pointed to the same place before landing on a genuine Microsoft authorization page. Depending on what was approved, the attacker-controlled app could reach mailbox, files, Teams, SharePoint, OneDrive, and calendar data.
The risk persists after the message is gone because the access comes from consent, not a stolen password. That makes OAuth grants and third-party app permissions a standing entry point into Microsoft 365, even for users who never touch Planner.