Security researchers at Kaspersky detected more than 31,000 fraudulent messages exploiting the Microsoft authentication system over a seven-week period between August 1 and September 18. Attackers sent deceptive electronic messages containing legitimate links to redirect corporate users to malicious portals or prompt unwanted software downloads. This operation targeted credentials by disguising communications as official account notices.
Mechanics of the Microsoft authentication system Abuse
To execute the redirection strategy, cybercriminals first established an account and accessed the Microsoft Entra admin center. Fraudsters then registered a new program in the application registration portal. During setup, attackers inserted an external address into the redirect Uniform Resource Identifier field, which normally directs authorized users to approved destinations after validation.
After configuring the program, attackers distributed messages featuring genuine links containing the registered application identification and custom address. Consequently, recipients following the prompt were guided to sites built to capture login records or deliver malicious payloads. Such manipulation disguises hostile activity behind legitimate cloud applications without raising initial suspicion.
Exploitation of Official Security Notifications
Attackers also devised an additional intrusion path by inserting rogue text directly into genuine platform notifications. Fraudsters achieved this access by obtaining trial access or buying basic service tiers. Next, the perpetrators altered the name field on the overview console to display deceptive statements.
The actors subsequently created fictional user profiles with fabricated identities and credentials. By logging into the official portal with those profiles, attackers registered target email addresses as secondary recovery accounts. As a result, victims received genuine verification codes containing hostile instructions directly in the subject line and signature area.
“It is not the first time we have observed that fraudulent links and messages are not sent ostensibly on behalf of the real company, but are sent through official services. This adds a dangerous layer of credibility, making the scam harder to spot.”
Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky
Defensive Measures and Security Operations
Kaspersky noted that conventional phishing detection markers often fail against threats transmitted through authorized service channels. Consequently, protecting corporate networks requires multi-layered filters and real-time monitoring across all communication channels. The incident confirms how online attackers continue probing the Microsoft authentication system to bypass standard filtering mechanisms.
Organizations handling modern threat environments apply defensive screening such as Kaspersky Security for Mail Server, which uses machine learning routines to inspect inbound traffic. For individual protection, consumer options such as Kaspersky Premium combine behavior tracking with account leakage monitors to maintain active cybersecurity defenses.
Industry Background and Response
Founded in 1997, Kaspersky develops protection tools serving critical infrastructure, business networks, and individual devices globally. The firm stated that its security network protects more than one billion endpoints and nearly 200,000 corporate entities worldwide. As deceptive campaigns adapt to enterprise verification tools, security specialists emphasize using automated threat identification to counteract sophisticated unauthorized access.