logo

Inside Job: Abandoned Outlook Add-in “AgreeTo” Steals 4,000 Credentials

ID: 9bf3475f-df11-543a-a0be-1cecb07f827a

STIX ID: report--9bf3475f-df11-543a-a0be-1cecb07f827a

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers at Koi Security discovered that the Outlook add-in 'AgreeTo' was hijacked after its developer let the Vercel-hosted URL expire; attackers claimed the URL, deployed a phishing kit served inside Outlook’s sidebar, and collected over 4,000 Microsoft account credentials, credit card numbers, and security answers. Because the phishing content was hosted on a legitimate domain and loaded within Outlook (with ReadWriteItem permissions), it bypassed usual gateways and endpoint protections and could read or modify users' emails, demonstrating a high-impact abuse of remote-hosted Office add-ins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.