# Beware: attackers now using real Microsoft sign-in screen for phishing

> **Open Intelligence Dossier** · First detected: 2026-07-31 15:07 UTC · Category: Technology

## Executive Summary
Cyber attackers are bypassing traditional security warnings by leveraging legitimate Microsoft login pages to conduct sophisticated phishing campaigns.

## Intelligence Brief
A new wave of cyberattacks is utilizing authentic Microsoft sign-in screens to deceive users into providing sensitive credentials. According to reporting from Cybernews and Help Net Security, attackers are using Microsoft&amp;#039;s own trusted login system to camouflage their phishing efforts, making the scams significantly harder to detect than traditional fake websites. These campaigns often incorporate specific themes to lure victims, with Infosecurity Magazine highlighting a particular campaign themed around Microsoft Teams. The objective of these attacks is to leverage the inherent trust users place in a genuine Microsoft interface to steal account information. Multiple industry outlets are tracking the evolution of these tactics.


The Check Point Blog notes that the trusted login system is being turned into a phishing weapon, while Infosecurity Magazine specifically identifies the abuse of legitimate login pages within Teams-themed attacks. Additionally, BusinessToday Malaysia has reported that businesses are being warned about scam tactics that utilize procurement-themed emails to target organizational members. This indicates a multi-pronged approach where attackers combine authentic login portals with professional-sounding lures to maximize their success rates against corporate targets. To understand the broader context of these threats, The Hacker News identifies device code phishing as the fastest-growing threat of 2026, citing six primary reasons for its rapid ascent. This trend aligns with a larger landscape of evolving toolsets, as CyberSecurityNews recently cataloged the top ten phishing kits used by hackers to launch cyberattacks between July 20 and July 26, 2026.


The shift toward using real sign-in screens represents a move away from easily detectable spoofed pages toward a method that exploits the actual infrastructure of the service provider to mislead the end user. Looking forward, the coverage suggests a continued focus on the proliferation of device code phishing and the deployment of advanced phishing kits. Organizations and individuals are advised to remain vigilant against procurement-themed emails and Teams-related lures that redirect to these authentic but weaponized login screens. Because these attacks utilize legitimate Microsoft pages, standard visual checks for fake URLs may no longer be sufficient. Future monitoring will likely center on how these specific phishing kits are updated to bypass emerging security defenses as the threat continues to grow through 2026.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| CyberSecurityNews | Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) | [Source Link](https://news.google.com/rss/articles/CBMidkFVX3lxTE1vUFhwb2xBR3dGUFBjdWdUNll2LW5PNWpRYmZfekRWR21wdHpBazZaMFJNdGNCd2tiMDVjN01tRUdhSVNYRGFNWVFLeXhCNEVzLTZ0MUswU1hWVHZlMG5oQm45ZUhkVnRtbzBpTkNSWDBQNWZpZGfSAXtBVV95cUxOTTlidnVtVG8wNEZDNmFHU1VaMDJVY1hhTWltakxiWDZYZlEwVE5Pakc3cDFyaXk3NVZMT1ZSUGZ6RG1sNnQ1WjVfOFVOZnEwOE15aVJzSUI0TkNHc01tWkRMS3RoQTlsU3VrM1hLNHpRU3pUOXRlaG9DMjQ?oc=5) |
| Infosecurity Magazine | Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages | [Source Link](https://news.google.com/rss/articles/CBMie0FVX3lxTE1zdEQyWC1qbERYdmVyYTFKLVRaWHNOV28yQnhlcjU4V1kxYzlHV0lRU0xiSEpXeXBJeDBZVjNDRzZUZWhqRUlJbFBxVkRHWEg3Z2xoelFBOU9iYjM2MUdGVlNSNG1VdmY0Q3N5WVFnZlMyOGpUanRVRnlSdw?oc=5) |
| Check Point Blog | Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon | [Source Link](https://news.google.com/rss/articles/CBMiywFBVV95cUxQTVZVRTI2eVVfWjhMU0paR3VWLU95cmhxU18zSmRQbThMaU1YZnpfbFdta2lCM2g1LVhGajhHblR4UkE1X3FHLVkxT3VlS3hoYVBIN1BkU3NhdFJnaVp2bFlYTV9PMC1rOVpCcjBBbTZ2SG5JcmNCZHBzbVdZOGk0Q1YtamxCNVVsR2x6WmlhZzZYMDNDZU14c3E0RlJ0c2JOT2tVZXdFdW9abjBjeGVwNVZCUXl6am5iT1QybFNOZUJZbEg5SVJXaElIcw?oc=5) |
| BusinessToday Malaysia | Businesses Warned Of Scam Tactics Using Procurement Themed Emails | [Source Link](https://news.google.com/rss/articles/CBMirwFBVV95cUxNSzZMSUFDVVhSdVdBa0hOT2wxbEVFbDlrZF92WHcteURHRVd6X3p0UVo5dGNuQi1yYnRrV1kyUTljSnVXTjVkT3BjTzFMaDZGMFhRLUxKQUFIQXBGYzF6NjZaRUR2c3BoRHpLMS02bkN1MEhSTXV1dS03U2V5bXg2eW1ZczJWTndUZGg4WEJjelQ5SlZMa2tka2R6M3pkcmdWc2VTb1J6bVc5X2ozeWxr?oc=5) |
| Help Net Security | Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks | [Source Link](https://news.google.com/rss/articles/CBMijAFBVV95cUxOOWNuU3BMZmJnbE5NNnNhVlVEVnJNNmJueHl3RG9ZQV83b0FmcHowbERnSUVpSnBvOHY2dW5RQXowSC1Fd0xOUU9laDc1QUtsUVdJcDFoRldLOVp0WkpmalZmZGhoM0ZPNFZSM0FNMzlELUdNdlBPOFFUa3Z5VDVYa3U3UlJYVDlwcDh0WA?oc=5) |
| The Hacker News | 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 | [Source Link](https://news.google.com/rss/articles/CBMiggFBVV95cUxNLWRyLXJjR3RwN1ZBY21IRU5GR1BxVnVWUnJhX3EzRUlRbFA5WmhBVEZBUFJHclhlUjVSM3diaVZHNy1wTnVzQWFnUGxLSmozM3R6elNxSG9KTFhtV1dObEhQLXRPbkd2d0dRWnFwdUJWR2tEckpmQVpRc3Z1STdYZ0tR?oc=5) |
| Cybernews | Beware: attackers now using real Microsoft sign-in screen for phishing | [Source Link](https://news.google.com/rss/articles/CBMifkFVX3lxTE1xSjdXSDhSQ0ZZeW0yY21VY2dCdThtMFJyNmN6Y1UyUV85ZEFyN3QxV2FsVHNKUkdQeVNqendxejd6MGRMQ2ZoN3I0UmpOUDlubDhpM1I1UUk5QWdTY2FQU0IxcnJPcDZrYXRqcnRxbi1EUXFodlh6ZmNxMDloQQ?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-07-31/beware-attackers-now-using-real-microsoft-sign-in-screen-for-phishing*
