Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for
No passwords were stolen, and MFA never came into it; they walked away with access to mail, files, Teams, SharePoint, and calendars across around 120 organizations.
A recent phishing campaign targeting Microsoft users has demonstrated a troubling shift in hacker tactics. Instead of focusing on stealing passwords, attackers have been using fake Microsoft Teams notifications to lure victims into granting permissions to malicious apps. This technique, known as "consent phishing," has become so widespread that it has been commoditized into a rentable service.
The campaign, which ran from late June to July 2026, affected users across approximately 120 organizations worldwide. The phishing emails appeared to be Microsoft Planner task-assignment notifications, complete with a sender name and subject line that appeared legitimate. Clicking through to the fake Microsoft Teams notification prompted users to approve permissions for an attacker-controlled app, granting them access to sensitive data such as mail, files, Teams, SharePoint, OneDrive, and calendars without defeating multi-factor authentication (MFA).
While multi-factor authentication effectively protects the login process, it does not safeguard access to user data post-login, as the attackers gained consent-based access through the user's valid session. To mitigate this threat, organizations should consider implementing stricter app consent checks and limiting access to sensitive permissions at the system administrator level.
It is crucial for users to remain vigilant and carefully review every permission or consent screen they encounter, even if it appears to come from a trusted source.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.