Microsoft Login Pages Hijacked in Sophisticated Phishing Campaigns
Security researchers at Barracuda have identified a series of phishing campaigns that use real Microsoft login pages, weaponised PDF attachments and a rare “split-click” technique to steal session tokens and bypass conventional email defences.
The findings, published in Barracuda’s Email Threat Radar for June 2026, flag a broader shift in attacker behaviour, with some campaigns moving away from credential theft and toward direct malware delivery using obfuscated scripts hidden inside fake invoices.
One campaign uses a genuine Microsoft login page to intercept users’ session tokens and access permissions. Victims receive a legitimate-looking warning that their inbox is nearly full, accompanied by a calendar invite to a meeting with Microsoft security.