Insights
The phishing page that let Microsoft do the reconnaissance
I spent a few minutes yesterday poking at a phishing page that behaved exactly like the real Microsoft 365 sign-in, because it was the real Microsoft 365 sign-in, relayed through the attacker's server. What made it worth writing about was not the theft of credentials but the quiet way it used Microsoft's own sign-in endpoints to work out, before a password was ever typed, whether it had caught a real account at the right company.
Peter Bassill15 min read · 5 reads