A phishing campaign has targeted corporate Outlook, SharePoint, and OneDrive accounts by exploiting Microsoft's legitimate authentication system. The attackers impersonated Microsoft Teams alerts and utilized OAuth URLs to mislead users into granting access to their accounts. The campaign affected 120 organizations, employing social engineering tactics to pressure users.
Researchers suggest methods to identify and protect against similar tactics, stressing the importance of verifying sender information and being cautious with links in emails.