Identity · 46 days ago
The weakness is the trust model, not the login page. If the page is real Microsoft, the usual advice to spot a fake sign-in screen stops working, and a user can hand over lasting access by approving an OAuth request instead of typing a password into a phony site.
Check Point says it saw 200+ phishing emails from June 25 into the second week of July, aimed at around 120 organizations. The lures used Microsoft Planner branding, internal-looking sender details, and multiple buttons that all pointed to the same place before landing on a genuine Microsoft authorization page. Depending on what was approved, the attacker-controlled app could reach mailbox, files, Teams, SharePoint, OneDrive, and calendar data.
The risk persists after the message is gone because the access comes from consent, not a stolen password. That makes OAuth grants and third-party app permissions a standing entry point into Microsoft 365, even for users who never touch Planner.
4 sources covering this story
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
A phishing technique abuses Microsoft's authentication system, using real login pages to trick users into granting attackers account access.
Hackers abuse Microsoft Teams in ransomware campaign through fake IT support
Researchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage.
Part of the PlainSec briefing for 2026-07-31