logo

Microsoft creates fake Azure tenants to pull phishers into honeypots

ID: 40ebe0e3-733e-5ce0-8d4d-8ae54fa90718

STIX ID: report--40ebe0e3-733e-5ce0-8d4d-8ae54fa90718

Feed Name: Bleeping Computer

Threat Score
20/100

Date Published: 2024-10-19

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft operates a deception program that spins up realistic Azure tenant honeypots (custom domains, ~20k user accounts) and actively submits credentials to phishing sites to lure attackers in; when adversaries log in (about 5% of seeded sites), Microsoft logs detailed activity (IPs, browsers, behavior, phishing kits) to map infrastructure, attribute actors, and improve Defender protections, claiming thousands of blocked connections and an ability to waste attackers' time while gathering intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.