Skip to main content
Emerging ThreatsMalware & Ransomware

Phishing Campaign Exploits Microsoft Authentication

Laptop on a desk in a bright office setting displays a notification on a Microsoft Teams interface.

“Attackers have stopped forging Microsoft’s front door and started walking through it. Every screen the victim sees is authentic, the only fake thing in this entire chain is the intent behind the app requesting access,” Check Point wrote in a July 29 blog post describing a recent campaign that used Microsoft’s own authentication flow to steal access to corporate accounts.

Abuse of Microsoft’s OAuth authorize URL

Instead of cloning Microsoft login pages, the attackers in this campaign sent messages that routed victims to a legitimate OAuth authorize URL hosted by Microsoft. The emails were crafted to appear as Microsoft Teams notifications — in one variation disguised as a Microsoft Planner task-assignment with the display name “There’s New Activity On Teams.” The body referenced “overdue tasks” and claimed HR had sent messages on Teams, pressuring recipients to click.

If a victim clicked the link and attempted to sign in, the flow presented a prompt to “Approve permissions” or “Accept on behalf of your organization.” When the user granted consent, the login was redirected to attacker-controlled infrastructure and the attacker received an authorization token. With that token, the attackers could access the account through legitimate Microsoft 365 mechanisms.

Scope and targets: 120 organizations, June–July window

Check Point reported the campaign began in the final weekend of June and continued into July. The activity targeted users at 120 organizations across several sectors explicitly named in the report, including manufacturing, legal and healthcare. In some cases the message appeared to come from the recipient’s own email address while the display name asserted Teams activity — a combination intended to reduce suspicion.

Capabilities gained: Outlook, SharePoint, OneDrive access and BEC

Because the attackers acquired valid authorization tokens, Check Point said they “had the ability to access the account and could exploit this to do anything a legitimate user could do with their Microsoft 365 suite.” The researchers spelled out immediate consequences: reading messages, exfiltrating data from inboxes, and using a legitimate, trusted account as a springboard for Business Email Compromise (BEC) attacks.

Even though this particular campaign is no longer active, Check Point framed it as “yet another example of how attackers have fundamentally changed how they’re bypassing traditional phishing defenses,” underscoring that the mechanics of the compromise hinge on misuse of legitimate consent flows rather than on forged login screens.

Detection and mitigation steps recommended by Check Point

  • Hover over links before clicking and check whether the destination matches the service referenced in the message. Be suspicious when different buttons lead to the same URL.
  • Verify that the sender name, sender address, and sending domain are consistent. In this campaign, the message appeared to come from the recipient’s own email address, while the display name claimed to represent Teams activity.
  • Do not trust an email simply because it appears to come from an internal address. Display names and sender addresses can be spoofed or manipulated.
  • When uncertain, open Teams or other applications directly through the official app rather than using links in the email.

What this means for technologists, affected enterprises, and end users

Technologists and security teams: The shift described by Check Point — from forged login pages to legitimate OAuth consent abuse — means incident responders and detection engineers will need to monitor for anomalous OAuth authorize-url flows and suspicious application consent patterns, since the visible screens presented to users are authentic.

Affected enterprises and procurement leaders: Organizations in sectors named by Check Point, including manufacturing, legal and healthcare, should review how application consent is governed and consider controls that limit the ability of users to grant broad third‑party permissions without oversight.

End users and general staff: The practical guidance in the report is simple and actionable — hover over links, confirm sender details, and when in doubt access Teams or other services directly through the official app rather than an email link.

For defenders, the lesson is specific: attackers will increasingly rely on legitimate authentication channels to mask intent. For everyone else, the visible screens may be genuine; the consent is not. Check Point’s account of the June–July campaign is a reminder that phishing protections calibrated to spot fake login pages are no longer sufficient on their own.

https://www.infosecurity-magazine.com/news/teams-phishing-abused-legit/