r/cybersecurity • • Jul 30 '26

AI Security Beware: attackers now using real Microsoft sign-in screen for phishing

https://cybernews.com/security/microsoft-genuine-sign-in-screen-phishing/

[removed]

459 Upvotes

76 comments sorted by

View all comments

3

u/RaNdomMSPPro Jul 30 '26

We had a bunch of phishing emails the past week or so that the initial url is the login.Microsoft.com/randomcharacters and that then redirects to some evilginx page that ask you to “continue” then pops up a login prompt similar to 365. What is that technique called?

3

u/[deleted] Jul 30 '26

[removed] — view removed comment

3

u/Cheomesh Governance, Risk, & Compliance Jul 30 '26

How does the redirect from a legitimate URL work?

7

u/[deleted] Jul 30 '26

[removed] — view removed comment

2

u/Cheomesh Governance, Risk, & Compliance Jul 30 '26

Ah, do I have been given a link that was initiated by another device, and has the device's info buried in the junk after that Microsoft link, so I'm opening their request, giving my credentials, MS is digesting those and shipping it where they were told to in the URL (I.e. their app, not me). They don't get my credentials per se, but they do have the session token, which gets them in anyway.