Skip to content

Phishing Campaign Abuses Genuine Microsoft Login Page for OAuth Consent Attack

Bottom line: A phishing campaign bypasses classic login-spoofing detection by tricking victims into granting OAuth permissions to an attacker-controlled app via the genuine Microsoft login page.

Check Point Research has identified a phishing campaign that sent over 200 emails to employees at roughly 120 organizations worldwide. Instead of a fake login page, the attackers used the legitimate Microsoft login to induce victims into granting permissions to a malicious application.

According to Check Point Research, more than 200 phishing emails were sent to employees at around 120 organizations worldwide. The key difference from classic credential-phishing attacks: the campaign did without a replicated, fake Microsoft login page. Instead, victims were redirected directly to the genuine Microsoft login page. Following regular authentication, the campaign prompted users to grant access permissions to an application controlled by the attackers.

For CISOs, this approach is significant because it circumvents common defense mechanisms. Classic anti-phishing filters and awareness training are typically designed to detect fake domains, deviating URLs, or atypical login forms. Since the actual Microsoft infrastructure is used here, many of these detection markers are absent. The attack shifts from credential theft to abuse of OAuth consent mechanisms: users authenticate correctly, but in the next step grant permissions to a malicious third-party application — for example, to mailboxes, files, or other resources accessible via Microsoft Graph.

In practice, this means organizations should supplement their controls with application consent policies in Entra ID (formerly Azure AD). This includes restricting user consent to verified publishers, introducing admin consent workflows for new applications, and regularly auditing already-granted app permissions. Security teams should also establish monitoring rules to detect unusual OAuth grant activity, as this can appear inconspicuous in classic login logs.


Source: www.security-insider.de · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: