Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Rahim Amir

Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for

A laptop with digitally inserted hack warnings around it.
  • Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page
  • Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA
  • Check Point says the technique has been commoditized in 2026 into a rentable service; the practical defense is restricting app consent rather than relying on users to spot a fake

A phishing campaign that ran from late June into July 2026 did something that breaks most of the advice organizations have spent a decade teaching their staff: it sent victims to a real Microsoft login page.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.