{
  "id": 149971,
  "title": "Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for",
  "url": "https://urgent.news/2026/08/04/watch-out-microsoft-login-pages-are-being-abused-as-hackers-try-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-04T23:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/watch-out-microsoft-login-pages-are-being-abused-as-hackers-try-and-lure-in-unlucky-victims-heres-what-to-look-out-for"
  },
  "original_language": "en",
  "account": "A recent phishing campaign targeting Microsoft users has demonstrated a troubling shift in hacker tactics. Instead of focusing on stealing passwords, attackers have been using fake Microsoft Teams notifications to lure victims into granting permissions to malicious apps. This technique, known as \"consent phishing,\" has become so widespread that it has been commoditized into a rentable service. The campaign, which ran from late June to July 2026, affected users across approximately 120 organizations worldwide. The phishing emails appeared to be Microsoft Planner task-assignment notifications, complete with a sender name and subject line that appeared legitimate. Clicking through to the fake Microsoft Teams notification prompted users to approve permissions for an attacker-controlled app, granting them access to sensitive data such as mail, files, Teams, SharePoint, OneDrive, and calendars without defeating multi-factor authentication (MFA). While multi-factor authentication effectively protects the login process, it does not safeguard access to user data post-login, as the attackers gained consent-based access through the user's valid session. To mitigate this threat, organizations should consider implementing stricter app consent checks and limiting access to sensitive permissions at the system administrator level. It is crucial for users to remain vigilant and carefully review every permission or consent screen they encounter, even if it appears to come from a trusted source.",
  "summary": "No passwords were stolen, and MFA never came into it; they walked away with access to mail, files, Teams, SharePoint, and calendars across around 120 organizations.",
  "key_points": [
    "Hackers use fake Microsoft Teams notifications to trick users into granting app permissions.",
    "\"Consent phishing\" technique has been commoditized into a rentable service."
  ],
  "editors_take": "This phishing tactic shift to exploiting post-login vulnerabilities highlights a need for organizations to reassess their security measures beyond multi-factor authentication to protect sensitive user data.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}