Beware: attackers now using real Microsoft sign-in screen for phishing
Every screen the victim sees is real.

Image by Cybernews.
- Phishers now weaponize genuine Microsoft sign-in pages, defeating traditional fake-login detection training.
- Fake Teams HR lures trick users into granting app access, bypassing password theft.
- Campaign hit 120 organizations globally, showing consent phishing is scalable and increasingly commoditized.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Forget fake login pages. That’s the advice of Check Point, a cybersecurity company, whose researchers have uncovered a campaign where attackers actually use Microsoft’s genuine sign-in screen.
According to Check Point, the process looks like this: first, victims receive an email that appears to be a Teams task from HR. That’s the lure.
The sender’s name is “There’s New Activity On Team,” and the subject line is “HR@[company].com Sent 3 Messages Via Teams Chat”.
The body closely mimics Teams' styling and references a “Payroll, Compensation + Benefits Update,” alongside a “4 Overdue Employee Tasks” counter intended to create urgency and encourage a quick click.
They click and land on a genuine login.microsoftonline.com page: no spoofed URL, no red flags, nothing employees were ever trained to spot.
Then it asks them to “approve” an app. One crucial click later, attackers have a foothold in that person’s email, Teams, SharePoint, OneDrive, and calendar – all without ever stealing a password.
Researchers have identified more than 200 unique phishing emails that targeted users across approximately 120 organizations in two weeks, spanning a wide range of industries and countries worldwide. And it’s not a one-off.
“This technique is already common and becoming increasingly widespread. It is a named and tracked technique in the MITRE ATT&CK framework, and in 2026, it evolved from a targeted, manually built attack into a service that virtually anyone can rent,” warns Check Point in a blog post.
Check if your data has been leaked
“It’s gone from bespoke attacks built by skilled hackers to something anyone can rent off the shelf.”
The crooks in this particular case have targeted organizations in North America, hitting industries, legal services, and non-profits.
The campaign is no longer active, Check Point points out. But continuous vigilance is advised since, clearly, attackers have “fundamentally changed how they’re bypassing traditional phishing defenses.”
Do not trust an email simply because it appears to come from an internal address.
“Attackers have stopped forging Microsoft’s front door and started walking through it. Every screen the victim sees is authentic – the only fake thing in this entire chain is the intent behind the app requesting access,” say the researchers.
What can you do? First and foremost, carefully pause and hover over links before clicking:
- Check whether the destination matches the service referenced in the message, and be suspicious when different buttons lead to the same URL.
- Verify that the sender name, sender address, and sending domain are consistent. In this campaign, the message appeared to come from the recipient’s own email address, while the display name claimed to represent Teams activity.
- Do not trust an email simply because it appears to come from an internal address. Display names and sender addresses can be spoofed or manipulated.
- When uncertain, open Teams or other applications directly through the official app rather than using links in the email.
- Finally, report suspicious messages immediately. Early reporting allows security teams to investigate the application, revoke malicious consent, identify affected accounts, and block related campaign activity.
The threat isn’t exactly new. Already in February, Abnormal AI researchers identified a new phishing platform, Starkiller, that gives cybercriminals a more convincing way to steal login details – using real websites that victims trust instead of fake copies.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Rather than building imitation login pages, Starkiller also loads legitimate sites live and sits between the victim and the real service, capturing data as it passes through.