Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages

Cybersecurity researchers have identified a phishing campaign that impersonates Microsoft Teams notifications to steal corporate credentials. Attackers are bypassing traditional security by using legitimate Microsoft authentication infrastructure to deceive users.
Why it matters
This highlights a dangerous evolution in social engineering where attackers leverage trusted platforms to bypass standard security filters.
A recent hacking campaign impersonated notifications from Microsoft Teams and abused Microsoft’s legitimate authentication infrastructure to compromise corporate Outlook, SharePoint and OneDrive accounts.
In a blog post published on July 29 , cybersecurity researchers at Check Point warned that attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure.
By employing this tactic, attackers hope that their phishing campaigns have a higher chance of being successful by avoiding some of the telltale signs of suspicious activity which users may be aware of.
The campaign started in the final weekend of June and continued into July, targeting users at 120 organizations including manufacturing, legal and healthcare, with emails designed to look like a notification alert for Microsoft Teams from the company’s HR department.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in