Back Cybernews Beware: attackers now using real Microsoft sign-in screen for phishing
Forget fake login pages. That’s the advice of Check Point, a cybersecurity company, whose researchers have uncovered a campaign where attackers actually use Microsoft’s genuine sign-in screen.
According to Check Point, the process looks like this: first, victims receive an email that appears to be a Teams task from HR. That’s the lure.
The sender’s name is “There’s New Activity On Team,” and the subject line is “HR@[company].com Sent 3 Messages Via Teams Chat”.
The body closely mimics Teams' styling and references a “Payroll, Compensation + Benefits Update,” alongside a “4 Overdue Employee Tasks” counter intended to create urgency and encourage a quick click.
They click and land on a genuine login.microsoftonline.com page: no spoofed URL, no red flags, nothing employees were ever trained to spot.
Then it asks them to “approve” an app. One crucial click later, attackers have a foothold in that person’s email, Teams, SharePoint, OneDrive, and calendar – all without ever stealing a password.
Researchers have identified more than 200 unique phishing emails that targeted users across approximately 120 organizations in two weeks, spanning a wide range of industries and countries worldwide. And it’s not a one-off.
“This technique is already common and becoming increasingly widespread. It is a named and tracked technique in the MITRE ATT&CK framework, and in 2026, it evolved from a targeted, manually built attack into a service that virtually anyone can rent,” warns Check Point in a blog post .
“It’s gone from bespoke attacks built by skilled hackers to something anyone can rent off the shelf.”
The crooks in this particular case have targeted organizations in North America, hitting industries, legal services, and non-profits.
The campaign is no longer active, Check Point points out. But continuous vigilance is advised since, clearly, attackers have “fundamentally changed how they’re bypassing traditional phishing defenses.”
“Attackers have stopped forging Microsoft’s front door and started walking through it. Every screen the victim sees is authentic – the only fake thing in this entire chain is the intent behind the app requesting access,” say the researchers.
What can you do? First and foremost, carefully pause and hover over links before clicking:
The threat isn’t exactly new. Already in February, Abnormal AI researchers identified a new phishing platform, Starkiller , that gives cybercriminals a more convincing way to steal login details – using real websites that victims trust instead of fake copies.
Rather than building imitation login pages, Starkiller also loads legitimate sites live and sits between the victim and the real service, capturing data as it passes through.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
