Office 365 phishing scam uses Google Ad domains to evade security

(Image credit: Shutterstock)

A new phishing campaign that tries to steal users' Office 365 login credentials by tricking them into accepting a new Terms of Use and Privacy Policy has been discovered by researchers at the Cofense Phishing Defense Center (PDC).

This campaign has been observed across multiple organizations and employs a number of advanced techniques, including a Google Ad Services redirect, to try and steal employees' login credentials. 

Targeted users first receive an email sent with high importance that has the subject line “Recent Policy Change”. The email also comes from an address that contains the word security to help create a sense of urgency. The body of the email asks users to accept newly updated “Terms of Use & Privacy Policy” or else they may no longer be able to use the service.

The email contains two buttons (Accept and Learn More) and clicking on either button redirects users to a duplicate of the authentic Microsoft login page.

In order to get users to click on their phishing email, the attackers have utilized a Google Ad Services redirect which suggests that they may have paid to have their URL go through an authorized source. This also helps the campaign's emails easily bypass secure email gateways which are used by organizations to prevent phishing attacks and other online scams.

Once a user is redirected to the fake Microsoft login page, they are presented with a pop up of the privacy policy mentioned in the email. This window also contains both a Microsoft logo as well as the user's company's logo to make it appear more legitimate. The 'updated privacy policy' mentioned in the email is also taken directly from Microsoft's website.

After accepting the updated policy, the user is then redirected again to a Microsoft login page that impersonates the official Office 365 login page. If an employee enters their credentials on this page and clicks “Next”, the cybercriminals will then have their Microsoft credentials and will have compromised their account. 

To trick users into thinking they didn't just have their credentials phished, another box appears which reads “We've updated our terms” with a “Finish” button underneath this message.

This phishing campaign uses a lot of clever tricks to try and steal users' credentials which is why users should be extra cautious when opening any emails that appear to come directly from an official source and ask them to login to one of their accounts.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Latest in News
Man having Windows 11 problems with his laptop
Fed up of adverts creeping into Windows 11? You won’t like Microsoft’s latest update, then, although it does provide some important bug fixes
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Google Chromecast 2
Chromecasts are still broken – but Google tells fuming owners not to factory reset their devices
ChatGPT
ChatGPT wants to write your next novel, and readers and writers alike should be very worried
Garmin Instinct 3 next to the Apple Watch Ultra 2
New figures claim the smartwatch market just shrunk for the first time ever, and the Apple Watch Ultra 3 is to blame
Hitman: World of Assassination on PSVR 2.
Hitman: World of Assassination hits PSVR 2 soon, finally giving you a reason to dust off your headset