
Phishers Abuse DocuSign, Rewards, and “Verification”
This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…
Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When victims approved the requested permissions, the attackers obtained an authorization token and could access Microsoft 365 data like Outlook, SharePoint, and OneDrive. The compromised mailbox could also be used as a launchpad for business email compromise (BEC).
This campaign impersonated Microsoft Teams and Planner notifications, framing the email as if a company's HR department had sent messages through Teams. The sender display name read "There's New Activity On Teams," and the body referenced overdue tasks to create a sense of urgency. Instead of directing victims to a fake login page, the attackers routed them through Microsoft's real OAuth authorization flow. Once a user signed in, they were presented with a legitimate-looking prompt to "Approve permissions" or "Accept on behalf of your organization." Approving that request handed the attacker a valid authorization token without ever exposing a password.
Using Microsoft's own sign-in and consent screens removed one of the most reliable red flags defenders rely on: a suspicious or spoofed login page. Because the URLs and screens were authentic, technical inspection alone would not have revealed the malicious intent. The urgency created by referencing "overdue tasks" added pressure, and the HR/Teams framing made the message feel routine and internal rather than external and suspicious. The campaign reached users across manufacturing, legal, and healthcare organizations, suggesting a broad, opportunistic targeting approach rather than a narrowly tailored one.
Once an attacker obtains an OAuth authorization token, they can access Microsoft 365 data such as Outlook, SharePoint, and OneDrive, and a compromised mailbox can be reused for business email compromise. Because this method does not require stealing a password, awareness needs to extend beyond password hygiene:
These habits are especially relevant for finance, HR, executive assistants, and IT helpdesk or identity teams, who are frequently targeted because of the access and approvals tied to their roles.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers sent emails disguised as Microsoft Teams and Planner notifications from a company's HR department, then routed victims through Microsoft's legitimate OAuth authorization flow to request permissions.
Because the sign-in and consent screens were Microsoft's actual pages rather than fake login clones, the request looked trustworthy while the attacker still received an authorization token upon approval.
With a valid authorization token, attackers could access Microsoft 365 data such as Outlook, SharePoint, and OneDrive, and use the compromised mailbox as a launchpad for business email compromise.
The campaign targeted users at 120 organizations in manufacturing, legal services, and healthcare.
You get an email: sender name says “There’s New Activity On Teams,” and HR supposedly pinged you about overdue tasks. You click, and here’s the sneaky part: it sends you to Microsoft’s real sign-in and OAuth consent screens, asking to “Approve permissions” or even “Accept on behalf of your organization.” If you approve, you’ve basically handed an attacker an authorization token, so they can quietly read your Outlook, SharePoint, and OneDrive, and even use your mailbox for business email compromise. So if an email about Teams or HR tasks pushes urgency and then pops an unexpected Microsoft “Approve permissions” screen, stop, close it, and open Teams or Planner directly yourself to check.

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

Microsoft observed real-world campaigns where victims were tricked by “ClickFix” prompts into pasting a command into Windows Run, which then installed ACR…

Researchers documented a real phishing-as-a-service platform called Forg365, sold via Telegram, that helps attackers take over Microsoft 365 accounts using…