VYPR
researchPublished Jul 30, 2026· 2 sources

Attackers Abuse Microsoft Authentication for Sophisticated Phishing Campaigns

Threat actors are increasingly leveraging Microsoft's legitimate authentication system to bypass security controls and conduct sophisticated phishing attacks, researchers report.

Cybercriminals are evolving their tactics, moving away from traditional fake login pages and instead exploiting Microsoft's own authentication infrastructure to launch more evasive phishing campaigns. Researchers from Check Point have identified a significant trend where attackers are abusing the Microsoft Entra ID (formerly Azure AD) OAuth authorization process to trick users into granting access to their Microsoft 365 environments.

Between late June and mid-July 2026, security analysts observed over 200 phishing emails targeting approximately 120 organizations across various industries and geographical locations. These emails were cleverly disguised as legitimate Microsoft Planner task-assignment notifications. They often included fabricated details about HR updates or overdue employee tasks to create a sense of urgency, prompting recipients to click on embedded links.

A key element of this attack is the use of Microsoft's own legitimate login system. When a user clicks on a malicious link within the phishing email, they are directed to a genuine login.microsoftonline.com OAuth authorization page. This URL, being part of Microsoft's trusted domain, is less likely to trigger immediate suspicion from users or automated security filters. The email's visible sender address was also often spoofed to appear as if it originated from within the target organization, further enhancing its credibility.

Once the user proceeds, they are presented with a permissions request screen, asking them to authorize an application to access their account or organization's data. If the user grants this permission, Microsoft redirects their browser to an endpoint controlled by the attackers, often hosted on AWS API Gateway. This endpoint receives an authorization token, which the threat actors can then exchange for access to the victim's Microsoft 365 account.

The level of access gained by the attackers depends entirely on the permissions the user inadvertently approved. This can range from reading emails and files to accessing sensitive data within Teams chats, SharePoint, OneDrive, and calendar entries. Check Point highlighted that this technique is not entirely new and is recognized within the MITRE ATT&CK framework, but it has rapidly evolved from a manually crafted, targeted attack into a readily available service that can be rented by less sophisticated actors.

This sophisticated approach represents a fundamental shift in how attackers are circumventing traditional phishing defenses. By co-opting legitimate authentication flows and infrastructure, threat actors can bypass many of the security awareness training and technical controls designed to detect malicious links or fake login pages. The campaign identified by Check Point is reportedly no longer active, but it serves as a stark warning about the ongoing innovation in phishing techniques.

To mitigate such threats, Check Point advises users to exercise caution by hovering over links before clicking to inspect their destination, even if they appear legitimate. Users should also be wary if multiple call-to-action buttons within a single email all lead to the same URL. Verifying sender details, including the display name, address, and domain, is crucial, as display names can be easily spoofed even when the email address appears internal. This evolving threat landscape necessitates continuous vigilance and adaptation of security strategies.

This campaign, active since late June, specifically targeted users at 120 organizations across manufacturing, legal, and healthcare sectors. The phishing emails were disguised as Microsoft Planner task-assignment notifications, claiming HR had sent messages on Microsoft Teams and referencing "overdue tasks" to pressure recipients into clicking the malicious link.

Synthesized by Vypr AI