logo

Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts

ID: c3191b82-19fb-59e2-8f17-7ed743fa0c13

STIX ID: report--c3191b82-19fb-59e2-8f17-7ed743fa0c13

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-02-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious actor hijacked the abandoned AgreeTo Outlook add-in on the Microsoft Marketplace and converted it into a phishing kit that served a fake Microsoft login in the Outlook sidebar, stealing over 4,000 Microsoft account credentials plus financial data. The add-in loaded resources from a Vercel-hosted URL claimed by the attacker, exfiltrated credentials via a Telegram bot, and redirected victims to the real Microsoft login to reduce suspicion; the module also retained ReadWriteItem permissions. Koi Security discovered the compromise and Microsoft removed the add-in after the findings were reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.