Hackers spoof new Azure AD and Microsoft 365 sign-in pages
Nefarious hackers waste no time spoofing new sign-in pages

Microsoft has discovered that hackers have been hard at work revamping their phishing campaigns to use the new Azure AD and Microsoft 365 sign-in pages.
According to a tweet from the company: “Office 365 ATP data shows that attackers have started to spoof the new Azure AD sign-in page in multiple phishing campaigns. We have so far seen several dozens of phishing sites used in these campaigns.”
The Azure AD sign-in experience underwent a redesign about three months ago, but the new sign-in pages didn’t roll out until the first week of April.
Microsoft intended the redesign to reduce bandwidth requirements when loading Azure AD sign-in pages. The new design also made it easier for potential victims to determine when an attacker with outdated phishing tools targeted them. Now, it appears hackers have updated their tools to include updated sign-in pages.
With their spoofed paged now up to date, hackers are back to their old tricks. By sending out emails with the subject line “Business Document Received,” hackers have tricked unsuspecting users into opening fake PDFs. For some recipients, opening these malicious PDFs leads them to the new Azure AD or Microsoft 365 sign-in pages.
Microsoft’s Security Intelligence team said of the spoofed pages: “Microsoft Threat Protection provides comprehensive protection against these threats. Office 365 ATP catches ever-changing threats by exposing and detecting malicious behavior using detonation and machine learning. Microsoft Defender ATP blocks malicious documents on endpoints.”
Microsoft has addressed the spoofed pages, but Azure AD and Microsoft 365 aren’t the only Microsoft products malicious actors have targeted. Just a few weeks ago, a series of phishing attacks used images from automated Microsoft Teams notifications to steal Office 365 credentials from unsuspecting users. The company’s Sway service was also recently impacted by a highly targeted spear-phishing campaign that’s since been dubbed PerSwaysion.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Microsoft is ending support for the Remote Desktop app – here are three alternatives you can try instead
News Microsoft has announced plans to end support for its Remote Desktop application in just over two months.
By George Fitzmaurice
-
Microsoft's huge AI spending has investors worried – now the company is changing its financial reporting to highlight successes
News The move comes as investors want more evidence that Microsoft’s AI investment will pay off
By Nicole Kobie
-
Could Python in Excel be a boon for cryptocurrency miners?
Opinion Free Python compute resource on offer via Microsoft 365 beta preview – what could possibly go wrong?
By Richard Speed
-
Microsoft defends “negligent” security approach that prolonged vulnerability fix for five months
News The tech giant has refuted claims that its practices have left customers “in the dark”
By Ross Kelly
-
Microsoft Build 2023: Microsoft Fabric and oodles of Azure AI integrations announced
News Microsoft Fabric aims to greatly improve developer productivity and simplify real-time analytics
By Ross Kelly
-
Five ways to reduce Kubernetes costs
Tutorials With cutting expenditure a business imperative, there are several ways enterprises can reduce Kubernetes costs
By Ross Kelly
-
Azure spending notifications for customers unavailable until March, Microsoft warns
News Customers have been advised to manually monitor Azure usage and costs until a fix is implemented
By Ross Kelly
-
Microsoft cloud revenue still sky-high as device sales continue to slide
News The company's latest earnings call revealed that Azure cloud products delivered better-than-expected results while numbers in other divisions fell substantially
By Ross Kelly