A real login page doesn't always mean you're safe

A real login page doesn’t always mean you’re safe

For years, one piece of security advice has been repeated.

Before you sign in, check you’re on the genuine website.

It’s still good advice.

The problem is that attackers have found ways to work around it.

A new type of phishing attack is catching people out because the login page really is Microsoft’s.

There isn’t a fake website asking for your username and password. There isn’t a suspicious web address to spot. The final sign-in page is completely genuine.

It usually starts with an email. It might look like a legal notice, a shared document, or something else that creates a sense of urgency.

Somewhere along the way you’re asked to copy a short code and paste it into Microsoft’s sign-in page.

That code looks harmless. After all, you’re logging into a real Microsoft website.

The trouble is, that code isn’t proving who you are to Microsoft.

It’s giving permission for someone else’s device to access your account.

Microsoft includes this feature to help devices without a keyboard, such as smart TVs or meeting room equipment, sign into an account.

Instead of typing a password on the device itself, you enter a code on another device that’s easier to use.

Attackers have found a way to misuse that process.

If someone persuades you to approve a code they created, Microsoft assumes you’re authorizing that device.

Behind the scenes, the attacker can get permission to access your account without ever knowing your password.

That means they could potentially read emails, access files, or view Teams conversations.

What makes this more difficult is that many of the usual warning signs aren’t there.

The website is genuine, the login page is genuine. Even multi-factor authentication may not stop the attack if you approve the request yourself, because you’ve effectively told Microsoft that the login is legitimate.

That’s why this is becoming more of an awareness issue than a technical one.

If you receive an unexpected email asking you to open a document, follow a series of steps, or enter a code into Microsoft, stop for a moment before doing anything.

Ask yourself a simple question: Did I start this process?

If the answer is no, treat it with caution.

Remind your team that not every security check involves spotting a fake website.

Attackers are becoming much better at using genuine services in ways they were never intended to be used.

That means awareness training needs to evolve as well.

If you’d like to review how well your business is protected against the latest phishing techniques, or you’d like help keeping your team up to date with the tactics attackers are using, get in touch.