Real Microsoft sign-in pages fuel consent phishing at scale
Cybersecurity researchers report attackers are using genuine Microsoft sign-in screens to run consent phishing, luring victims with HR-themed Teams emails and prompting approvals on real login pages. A single click grants attackers access to users’ email, Teams, SharePoint, OneDrive and calendar without stealing passwords, impacting about 120 organizations across various sectors in two weeks and evolving into an off-the-shelf service. Mitigations include hovering over links, verifying sender details, opening apps directly from official sources, enabling 2FA, and promptly reporting suspicious messages.
