logo

First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials

ID: 1068c604-d280-5c07-834d-be4740aaf320

STIX ID: report--1068c604-d280-5c07-834d-be4740aaf320

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers from Koi Security identified a supply-chain phishing campaign dubbed "AgreeToSteal" in which an attacker took control of an abandoned Outlook add-in's hosting domain and served a fake Microsoft login page, stealing over 4,000 credentials; the add-in's ReadWriteItem permissions also created risk of mailbox exfiltration and broader compromise, prompting recommendations for periodic rescanning, domain ownership verification, and re-review of changed content in the Microsoft Marketplace.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.