Briefing

Microsoft Uncovers Large-Scale Credential Theft Campaign Using Legitimate Email Services

security
by [email protected] (The Hacker News) ·

Enable MFA on all Microsoft accounts and block the attacker domains listed in the report immediately.

What to do now

Enable MFA on all Microsoft accounts and block the attacker domains immediately.

Summary

Microsoft has disclosed a large-scale credential theft campaign that operated between April 14 and 16, 2026. The attackers used code‑of‑conduct themed lures combined with legitimate email services to redirect users to attacker‑controlled domains. Over 35,000 users across more than 13,000 organizations in 26 countries were targeted. The campaign succeeded in stealing authentication tokens from victims, potentially granting attackers access to corporate resources. Microsoft identified the specific domains used by the attackers and the phishing vectors employed. The lures mimicked legitimate corporate communications, making them difficult to distinguish from genuine emails. The attack leveraged the trust users place in familiar email providers, bypassing basic email security controls.

Microsoft’s security team has issued a warning to all customers to verify the authenticity of emails and to be cautious of unexpected login prompts. The company recommends enabling multi‑factor authentication and reviewing account activity logs for anomalies. Microsoft has also provided a list of known malicious domains to block. The incident highlights the evolving sophistication of credential theft campaigns and the need for robust email security practices.

Organizations should immediately review their email filtering rules, enforce MFA across all Microsoft accounts, and block the attacker‑controlled domains identified by Microsoft. Regular security awareness training can help users recognize phishing attempts that mimic legitimate communications.

Key changes

  • Campaign ran April 14-16, 2026
  • Targeted 35,000+ users in 13,000+ orgs across 26 countries
  • Used code‑of‑conduct themed lures via legitimate email services
  • Redirected users to attacker‑controlled domains
  • Stole authentication tokens
  • Microsoft identified malicious domains
  • Advised MFA and domain blocking

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting