Critical🎣 Phishing
Microsoft 365 / Outlook Credential Phishing
Fake Microsoft 365 login pages — the world's most-cloned phishing target — steal employee credentials to breach corporate email, files, and cloud accounts.
Published: 20 February 2026Last updated: 18 March 2026
What Is This Threat?
Microsoft is the single most impersonated brand in phishing worldwide. Attackers create near-perfect copies of the Microsoft 365 login page to steal employee credentials. Once inside a corporate account, they can read emails, access SharePoint files, send internal fraud requests, and pivot to other systems.
How It Works
microsoftonline-secure.com or via a legitimate service (Google Docs, OneDrive link) used as a redirect.Why It's Dangerous for Businesses
Red Flags
login.microsoftonline.com.How to Protect Yourself
- Use phishing-resistant MFA such as hardware security keys (FIDO2) or Microsoft Authenticator number matching
- Enable Conditional Access policies in Azure AD to block logins from unexpected locations
- Train employees to check the URL before entering credentials — it must be login.microsoftonline.com
- Use Microsoft Defender for Office 365 to detect and block phishing emails
- Enable alerts for new email forwarding rules being set — a common attacker move
What to Do If Affected
- 1.Immediately revoke all active sessions in the Microsoft 365 admin portal
- 2.Change the compromised account password and re-enroll MFA
- 3.Check mail rules for any forwarding rules added by the attacker
- 4.Review sign-in logs in Azure AD for suspicious activity and locations
- 5.Report the incident to your IT/security team and Microsoft at microsoft.com/reportaphish
#Microsoft 365#Outlook#phishing#credentials#business#AiTM