LIVE: New phishing campaigns targeting mobile users —View latest threats →

Back to Threats
Critical🎣 Phishing

Microsoft 365 / Outlook Credential Phishing

Fake Microsoft 365 login pages — the world's most-cloned phishing target — steal employee credentials to breach corporate email, files, and cloud accounts.

Published: 20 February 2026Last updated: 18 March 2026

What Is This Threat?

Microsoft is the single most impersonated brand in phishing worldwide. Attackers create near-perfect copies of the Microsoft 365 login page to steal employee credentials. Once inside a corporate account, they can read emails, access SharePoint files, send internal fraud requests, and pivot to other systems.

How It Works

  • You receive an email: "Your Microsoft 365 session has expired", "You have a shared document waiting", or "Unusual sign-in activity detected."
  • The link leads to a fake login page at a domain like microsoftonline-secure.com or via a legitimate service (Google Docs, OneDrive link) used as a redirect.
  • You enter your email and password. Some attacks use Adversary-in-the-Middle (AiTM) proxies that relay your real login in real time, stealing your session cookie and bypassing MFA.
  • Attackers now have live access to your Microsoft 365 account — email, Teams, OneDrive, Azure AD.
  • Why It's Dangerous for Businesses

  • Access to one employee account often enables Business Email Compromise — sending fake invoice or wire transfer requests internally.
  • Attackers can silently set email forwarding rules to monitor your inbox for weeks.
  • Stolen Azure AD credentials can be used to access cloud infrastructure.
  • Red Flags

  • Email link goes to anything other than login.microsoftonline.com.
  • Requests your password even though you use Single Sign-On.
  • A "shared document" from someone you don't recognise.
  • How to Protect Yourself

    • Use phishing-resistant MFA such as hardware security keys (FIDO2) or Microsoft Authenticator number matching
    • Enable Conditional Access policies in Azure AD to block logins from unexpected locations
    • Train employees to check the URL before entering credentials — it must be login.microsoftonline.com
    • Use Microsoft Defender for Office 365 to detect and block phishing emails
    • Enable alerts for new email forwarding rules being set — a common attacker move

    What to Do If Affected

    1. 1.Immediately revoke all active sessions in the Microsoft 365 admin portal
    2. 2.Change the compromised account password and re-enroll MFA
    3. 3.Check mail rules for any forwarding rules added by the attacker
    4. 4.Review sign-in logs in Azure AD for suspicious activity and locations
    5. 5.Report the incident to your IT/security team and Microsoft at microsoft.com/reportaphish
    #Microsoft 365#Outlook#phishing#credentials#business#AiTM