#Microsoft 365
37 stories taggedMicrosoft 365 · page 2 of 3.

ACR Stealer Tricks Staff Into Typing the Attack Themselves
Microsoft says a fake-fix trick is pushing a data thief onto business PCs, walking off with passwords, session cookies and cloud files.

Forg365 Sells Ready-Made Microsoft 365 Hijacking Kits on Telegram for $400 a Month
A new phishing service hands criminals automated tools to break into Microsoft 365 accounts and stay there, even after a victim changes their password.

Forg365: A $400-a-Month Kit That Hijacks Microsoft 365 Logins
A new subscription phishing service uses device codes, session theft and AI-written lures to break into corporate email accounts.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time
A hacking group is phoning employees, sending them to fake Microsoft login pages, and quietly locking themselves into corporate accounts before anyone notices. Okta has the details.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then hoovers up company documents from Microsoft SharePoint.

Forg365: the new phishing kit built to hoover up Microsoft 365 logins
A fresh phishing-as-a-service operation uses AI to write the bait and a browser extension to keep the door open long after the theft.

Fake 'security upgrade' phone calls trick Microsoft 365 users into handing over their accounts
A criminal crew called Pink is calling staff, walking them through a fake Microsoft passkey setup, and quietly registering a login key of its own.

'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Fake Teams Invites Are Tricking Microsoft 365 Users Into Handing Over Their Accounts
A phishing crew is skipping the fake login page and walking victims straight through Microsoft's own device sign-in flow.

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users
Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into — and many victims had multi-factor authentication switched on, just not set up correctly.

New Phishing Kit 'ARToken' Exposes Full Microsoft 365 Takeover Playbook
Cisco Talos researchers found more than 80 hidden commands inside a phishing service tied to the EvilTokens platform — including tools to steal Microsoft 365 logins, read mailboxes, and quietly hide their tracks.

The Automation Nobody Reviewed: How AI-Built Workflows Are Quietly Leaking Enterprise Data
A developer asked an AI to speed up a document approval process. It worked perfectly — and exposed sensitive HR files to hundreds of colleagues. This is happening across businesses right now.

Microsoft restores missing Copilot buttons in Classic Outlook
A licensing bug wiped the AI assistant's buttons from the desktop email client. Microsoft says a June 29 fix has now landed.

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds
A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine — and a step-by-step guide is now circulating on a Russian crime forum.