logo

Microsoft Outlook Add-In Stolen 4000 Accounts and Credit Card Numbers

ID: 6cb5335b-b1a6-51f7-87b4-f6147d4f1e8a

STIX ID: report--6cb5335b-b1a6-51f7-87b4-f6147d4f1e8a

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Divya

...
...

A hijacked Outlook add-in (AgreeTo) was weaponized when an attacker claimed the add-in's expired hosting subdomain and served a phishing Microsoft sign-in page, exfiltrating credentials, credit card details, and banking responses from over 4,000 victims; the incident exposes a supply-chain/serving model weakness because Microsoft did not re-validate live add-in content after initial manifest approval, and the add-in's ReadWriteItem permission could have allowed mailbox access or mail-sending on victims' behalf.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.