The phishing page is real — attackers are stealing accounts through Microsoft's own login screen
Researchers at Check Point have documented a phishing campaign that does away with the fake login page altogether. The bait is an email dressed up as a Microsoft Planner task notification, claiming HR has shared payroll and benefits updates and listing several "overdue" tasks to create urgency. Click the link and you land on the genuine Microsoft sign-in page at login.microsoftonline.com — the real thing, with the real certificate.
You sign in as normal, complete MFA as normal, and are then shown a permission request. Approve it, and Microsoft itself redirects you to an attacker-controlled endpoint hosted on AWS API Gateway, which captures the authorisation token — handing the attacker access to the account without ever learning the password. Between 25 June and mid-July, Check Point counted over 200 phishing emails aimed at around 120 organisations across a spread of industries and countries.