💻
Hackers hijack Microsoft 365 accounts without stealing passwords — how to stay safe
💻 Technology

Hackers hijack Microsoft 365 accounts without stealing passwords — how to stay safe

A phishing campaign running from late June into July 2026 sent victims to a genuine Microsoft login page, then tricked them into approving permissions for an attacker-controlled app — bypassing MFA and gaining access to mail, files, Teams, SharePoint, OneDrive and calendars. Check Point identified over 200 such emails targeting users across roughly 120 organisations. The technique has been commoditised into a rentable service in 2026. The practical defence is restricting app consent permissions rather than relying on users to spot fake pages.

Comments

No comments yet