Security News > 2024 > July > Microsoft 365 users targeted by phishers abusing Microsoft Forms

There has been an uptick in phishing campaigns leveraging Microsoft Forms this month, aiming to trick targets into sharing their Microsoft 365 login credentials.
Malicious forms leading to phishing pages impersonating Microsoft 365 and Adobe.
Microsoft Forms is part of the Microsoft 365 product suite, and is used to gather feedback and information via survey, quizzes and polls.
The links take users to a Microsoft 365 or Adobe phishing page.
While Microsoft reacted to the threat by implementing automated phishing prevention to detect malicious password collection in forms and surveys, it's obvious that it's not always successful at recognizing malicious embedded links.
"Attackers enhance their forms' credibility by using convincing page titles and known favicons. Favicons are small icons displayed in the browser tab, and by using Microsoft familiar icons, attackers increase the perceived legitimacy of their fake pages. These visual cues can easily trick users into believing they are on a genuine Microsoft site," Perception Point researchers noted.
News URL
https://www.helpnetsecurity.com/2024/07/29/microsoft-365-phishing-forms/
Related news
- Microsoft: Licensing issue blocks Microsoft 365 Family for some users (source)
- Tycoon2FA phishing kit targets Microsoft 365 with new tricks (source)
- ActiveX blocked by default in Microsoft 365 because remote code execution is bad, OK? (source)
- Microsoft blocks ActiveX by default in Microsoft 365, Office 2024 (source)
- Attackers phish OAuth codes, take over Microsoft 365 accounts (source)
- Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts (source)
- New Microsoft 365 outage impacts Teams and other services (source)