Microsoft Outlook Add-In Stolen 4000 Accounts and Credit Card Numbers
ID: 6cb5335b-b1a6-51f7-87b4-f6147d4f1e8a
STIX ID: report--6cb5335b-b1a6-51f7-87b4-f6147d4f1e8a
Feed Name: GBHackers
A hijacked Outlook add-in (AgreeTo) was weaponized when an attacker claimed the add-in's expired hosting subdomain and served a phishing Microsoft sign-in page, exfiltrating credentials, credit card details, and banking responses from over 4,000 victims; the incident exposes a supply-chain/serving model weakness because Microsoft did not re-validate live add-in content after initial manifest approval, and the add-in's ReadWriteItem permission could have allowed mailbox access or mail-sending on victims' behalf.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
