- Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page
- Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA
- Check Point says the technique has been commoditized in 2026 into a rentable service; the practical defense is restricting app consent rather than relying on users to spot a fake
A phishing campaign that ran from late June into July 2026 did something that breaks most of the advice organizations have spent a decade teaching their staff: it sent victims to a real Microsoft login page.