Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
5 clusters · 20 sources · 30 days · First seen · Last updated
Phishing campaigns targeting Google and Microsoft platforms
Overview
In late July 2026, security researchers documented linked phishing operations spoofing Google Ads and abusing Microsoft’s OAuth 2.0 flow to hijack Outlook, OneDrive, and Teams sessions. Microsoft reported approximately 7.6 billion email-phishing attempts in Q2 2026, noting a surge in attacks via Teams and voice-phishing. Concurrently, CTM360 identified insurance-account hijacking via sponsored Google ads, primarily in Saudi Arabia but also in Europe, the US, and India.
By early August, attackers began exploiting authentic Microsoft sign-in pages. Over 200 fake Teams messages, masquerading as internal HR communications, directed users to genuine Microsoft domains to request permissions for malicious applications. In parallel, the Lumma Stealer malware circulated via counterfeit film-download executables to harvest passwords, browser data, and two-factor authentication tokens.
Mid-August developments show a 49 percent increase in phishing via calendar invitations. Attackers use malicious .ics files on platforms like Zoom and Google Calendar, often employing an ‘end-of-day-blur’ tactic to target users during periods of high cognitive load.
Further sophistication was identified in a business email compromise (BEC) campaign uncovered by TrendAI. This campaign used personalized spear-phishing emails regarding denied paid-time-off (PTO) requests to bypass multi-factor authentication (MFA). By utilizing adversary-in-the-middle (AiTM) relays to capture live authenticated session tokens, attackers hijacked Microsoft 365 sessions. They then implemented inbox rules to auto-archive vendor emails, allowing them to impersonate suppliers and redirect company payments for approximately 30 days.
Entities
Microsoft Teams · Google Calendar · KnowBe4 · SendGrid · Check Point Research
Timeline
-
6 days ago
[TECHNOLOGY] 3 sourcesMicrosoft 365 session theft campaign bypasses MFA to redirect paymentsAttackers bypassed Microsoft 365 multi-factor authentication using spear-phishing and session token theft to hijack finance mailboxes and redirect vendor payments to fraudulent accounts.
-
14 days ago
[TECHNOLOGY] 5 sourcesPhishing attacks using calendar invitations increase by 49 percentPhishing attacks using calendar invitations have increased by 49 percent, exploiting trust in platforms like Google and Microsoft to bypass email security.
-
19 days ago
[TECHNOLOGY] 7 sourcesMicrosoft phishing campaigns exploit real login pages and spoof security emailsPhishing campaigns now use real Microsoft login pages and fake Teams messages to steal credentials, while malware like Lumma Stealer disguises as film downloads to harvest passwords and crypto wallets.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesMicrosoft flags billions of email phishing threats and real-time insurance hijacking riseMicrosoft identified 7.6 billion email phishing attempts and a surge in Teams‑based vishing, while research shows insurance phishing now hijacks accounts in real time via Google‑ads, affecting multiple regions.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesPhishing campaigns spoof Google Ads sync and Microsoft OAuth to steal credentialsPhishing scams spoof Google Ads sync notices and Microsoft OAuth device flow, using fake emails to harvest credentials and gain access to users’ email, files, and Teams.
Sources
alignedinsurance.com · b2b-cyber-security.de · beerinbigd.com · bigdata-insider.de · borncity.com · cloudcomputing-insider.de · countryrebel.com · cybersecurityasean.com · gadgetsmagazine.com.ph · infopoint-security.de · mailhilfe.de · marler-zeitung.de · mobil.ruhrnachrichten.de · pymnts.com · security-insider.de · sf-encyclopedia.com · silicon.de · solidsoftwaretools.com · swr3.de · thehackernews.com
This summary has been updated 2 times: see revision history