Infosecurity-Magazine
Phishing Campaign Exploits Microsoft Authentication to Target Corporate Accounts
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A recent phishing campaign has exploited Microsoft's legitimate authentication infrastructure to compromise corporate Outlook, SharePoint, and OneDrive accounts. Cybersecurity researchers at Check Point reported that between June 25 and early July, over 200 phishing emails targeted around 120 organizations across various sectors, including manufacturing, legal, and healthcare. The emails masqueraded as Microsoft Planner task-assignment notifications, claiming HR had sent messages on Microsoft Teams. When users clicked the links, they were directed to a legitimate OAuth authorization page, where attackers captured their login credentials and authorization tokens. This allowed attackers to gain full access to the victims' accounts, facilitating potential Business Email Compromise (BEC) attacks. Although the specific campaign is no longer active, it highlights a significant shift in phishing tactics, moving away from fake login pages to leveraging legitimate systems. Check Point provided recommendations for organizations to enhance their defenses against such attacks.
Key Points: • Attackers exploited Microsoft's authentication system to bypass traditional phishing defenses. • Over 200 phishing emails targeted 120 organizations in various industries from late June to early July. • Victims were tricked into providing credentials via legitimate OAuth authorization pages.