Teams HR Phish Used Real Microsoft Login Flow

Infosecurity Magazine · High sophistication
Last updated July 30, 2026

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When victims approved the requested permissions, the attackers obtained an authorization token and could access Microsoft 365 data like Outlook, SharePoint, and OneDrive. The compromised mailbox could also be used as a launchpad for business email compromise (BEC).

How the attack worked

This campaign impersonated Microsoft Teams and Planner notifications, framing the email as if a company's HR department had sent messages through Teams. The sender display name read "There's New Activity On Teams," and the body referenced overdue tasks to create a sense of urgency. Instead of directing victims to a fake login page, the attackers routed them through Microsoft's real OAuth authorization flow. Once a user signed in, they were presented with a legitimate-looking prompt to "Approve permissions" or "Accept on behalf of your organization." Approving that request handed the attacker a valid authorization token without ever exposing a password.

Why it succeeded

Using Microsoft's own sign-in and consent screens removed one of the most reliable red flags defenders rely on: a suspicious or spoofed login page. Because the URLs and screens were authentic, technical inspection alone would not have revealed the malicious intent. The urgency created by referencing "overdue tasks" added pressure, and the HR/Teams framing made the message feel routine and internal rather than external and suspicious. The campaign reached users across manufacturing, legal, and healthcare organizations, suggesting a broad, opportunistic targeting approach rather than a narrowly tailored one.

What to watch for

  • Unexpected consent or permission prompts tied to a routine-seeming Teams or Planner notification
  • Sender display names that reference internal systems (like "Teams" or "HR") but do not match the actual sending address or domain
  • Messages that create urgency around overdue tasks or pending approvals
  • Requests to "Approve permissions" or "Accept on behalf of your organization" that were not initiated by the user

Building resistance

Once an attacker obtains an OAuth authorization token, they can access Microsoft 365 data such as Outlook, SharePoint, and OneDrive, and a compromised mailbox can be reused for business email compromise. Because this method does not require stealing a password, awareness needs to extend beyond password hygiene:

  • Open Teams, Planner, or other applications directly through the official app rather than clicking links in an email
  • Verify that the sender name, sender address, and sending domain are consistent before acting on a message
  • Treat unexpected permission or consent requests as a signal to pause and verify, even when the underlying page looks legitimate
  • Hover over links before clicking and confirm the destination matches the service referenced in the message

These habits are especially relevant for finance, HR, executive assistants, and IT helpdesk or identity teams, who are frequently targeted because of the access and approvals tied to their roles.

Key findings

  • Campaign impersonated Microsoft Teams notifications and HR messages to pressure users into clicking.
  • Instead of a fake login page, the attack used Microsoft’s legitimate OAuth authorization flow to appear trustworthy.
  • Victims were prompted to grant app permissions (including org-wide consent), which resulted in an attacker receiving an authorization token.
  • The campaign targeted users at 120 organizations across manufacturing, legal, and healthcare.
  • Compromised mailboxes could be used for data theft and as a springboard for BEC.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, Executive assistants, IT helpdesk / identity team.
  • Affected industries: Manufacturing, Legal services, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Company HR department / Microsoft Teams notification, Microsoft OAuth sign-in / consent flow (legitimate screens used for malicious intent).

Red flags to watch for

  • Email pressures action by referencing “overdue tasks”
  • Sender identity is inconsistent (looks internal but display name suggests Teams system alert)
  • Unexpected OAuth consent prompt asking to “Approve permissions”
  • Unexpected redirect after consent to non-corporate/unknown infrastructure
  • Consent prompt is not expected for a routine Teams/HR notification
  • Approving access may grant broad mailbox and file access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did this Teams phishing attack work?

Attackers sent emails disguised as Microsoft Teams and Planner notifications from a company's HR department, then routed victims through Microsoft's legitimate OAuth authorization flow to request permissions.

Why was this attack effective even though it used real Microsoft pages?

Because the sign-in and consent screens were Microsoft's actual pages rather than fake login clones, the request looked trustworthy while the attacker still received an authorization token upon approval.

What could attackers do after gaining access?

With a valid authorization token, attackers could access Microsoft 365 data such as Outlook, SharePoint, and OneDrive, and use the compromised mailbox as a launchpad for business email compromise.

Which industries were targeted?

The campaign targeted users at 120 organizations in manufacturing, legal services, and healthcare.

Read the video transcript

You get an email: sender name says “There’s New Activity On Teams,” and HR supposedly pinged you about overdue tasks. You click, and here’s the sneaky part: it sends you to Microsoft’s real sign-in and OAuth consent screens, asking to “Approve permissions” or even “Accept on behalf of your organization.” If you approve, you’ve basically handed an attacker an authorization token, so they can quietly read your Outlook, SharePoint, and OneDrive, and even use your mailbox for business email compromise. So if an email about Teams or HR tasks pushes urgency and then pops an unexpected Microsoft “Approve permissions” screen, stop, close it, and open Teams or Planner directly yourself to check.

Similar attacks

Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
M365 Device Code Phishing Bypasses User Suspicion

M365 Device Code Phishing Bypasses User Suspicion

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue login tokens directly to the attacker. Because the victim completes a legitimate MFA-approved sign-in on a legitimate Microsoft URL, the…

July 21, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Greatness PhaaS Adds Device-Code MFA Bypass

Greatness PhaaS Adds Device-Code MFA Bypass

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step…

August 4, 2026