< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

5 clusters · 20 sources · 30 days · First seen · Last updated

Phishing campaigns targeting Google and Microsoft platforms

Overview

In late July 2026, security researchers documented linked phishing operations spoofing Google Ads and abusing Microsoft’s OAuth 2.0 flow to hijack Outlook, OneDrive, and Teams sessions. Microsoft reported approximately 7.6 billion email-phishing attempts in Q2 2026, noting a surge in attacks via Teams and voice-phishing. Concurrently, CTM360 identified insurance-account hijacking via sponsored Google ads, primarily in Saudi Arabia but also in Europe, the US, and India.

By early August, attackers began exploiting authentic Microsoft sign-in pages. Over 200 fake Teams messages, masquerading as internal HR communications, directed users to genuine Microsoft domains to request permissions for malicious applications. In parallel, the Lumma Stealer malware circulated via counterfeit film-download executables to harvest passwords, browser data, and two-factor authentication tokens.

Mid-August developments show a 49 percent increase in phishing via calendar invitations. Attackers use malicious .ics files on platforms like Zoom and Google Calendar, often employing an ‘end-of-day-blur’ tactic to target users during periods of high cognitive load.

Further sophistication was identified in a business email compromise (BEC) campaign uncovered by TrendAI. This campaign used personalized spear-phishing emails regarding denied paid-time-off (PTO) requests to bypass multi-factor authentication (MFA). By utilizing adversary-in-the-middle (AiTM) relays to capture live authenticated session tokens, attackers hijacked Microsoft 365 sessions. They then implemented inbox rules to auto-archive vendor emails, allowing them to impersonate suppliers and redirect company payments for approximately 30 days.

Entities

Microsoft Teams · Google Calendar · KnowBe4 · SendGrid · Check Point Research

Timeline

  1. 6 days ago

    [TECHNOLOGY] 3 sources
    Microsoft 365 session theft campaign bypasses MFA to redirect payments

    Attackers bypassed Microsoft 365 multi-factor authentication using spear-phishing and session token theft to hijack finance mailboxes and redirect vendor payments to fraudulent accounts.

  2. 14 days ago

    [TECHNOLOGY] 5 sources
    Phishing attacks using calendar invitations increase by 49 percent

    Phishing attacks using calendar invitations have increased by 49 percent, exploiting trust in platforms like Google and Microsoft to bypass email security.

  3. 19 days ago

    [TECHNOLOGY] 7 sources
    Microsoft phishing campaigns exploit real login pages and spoof security emails

    Phishing campaigns now use real Microsoft login pages and fake Teams messages to steal credentials, while malware like Lumma Stealer disguises as film downloads to harvest passwords and crypto wallets.

  4. about 1 month ago

    [TECHNOLOGY] 3 sources
    Microsoft flags billions of email phishing threats and real-time insurance hijacking rise

    Microsoft identified 7.6 billion email phishing attempts and a surge in Teams‑based vishing, while research shows insurance phishing now hijacks accounts in real time via Google‑ads, affecting multiple regions.

  5. about 1 month ago

    [TECHNOLOGY] 2 sources
    Phishing campaigns spoof Google Ads sync and Microsoft OAuth to steal credentials

    Phishing scams spoof Google Ads sync notices and Microsoft OAuth device flow, using fake emails to harvest credentials and gain access to users’ email, files, and Teams.

Sources

alignedinsurance.com · b2b-cyber-security.de · beerinbigd.com · bigdata-insider.de · borncity.com · cloudcomputing-insider.de · countryrebel.com · cybersecurityasean.com · gadgetsmagazine.com.ph · infopoint-security.de · mailhilfe.de · marler-zeitung.de · mobil.ruhrnachrichten.de · pymnts.com · security-insider.de · sf-encyclopedia.com · silicon.de · solidsoftwaretools.com · swr3.de · thehackernews.com

This summary has been updated 2 times: see revision history