First Known Malicious Outlook Add-In Caught Stealing User Logins
Cybersecurity researchers found the first known harmful Microsoft Outlook add-in used in a real attack. The add-in, called AgreeTo, was once a normal calendar tool but was abandoned after 2022. An attacker took control of its expired web address and replaced it with a fake Microsoft login page. When users entered their passwords, the attacker stole them. Over 4,000 accounts were affected.
This happened because Outlook add-ins load content from a web link that can change over time. Microsoft checks the add-in when it is first approved, but it does not always monitor the live web content later. If a web address expires and someone else takes it, they can use it for phishing or other attacks.
How users can protect themselves:
- Avoid installing old or unused add-ins.
- Remove add-ins you no longer use.
- Turn on multi-factor authentication (MFA) for your Microsoft account.
- Check the web address carefully before entering your login details.
- Report suspicious login pages or unusual account activity.
Source: https://thehackernews.com/2026/02/first-malicious-outlook-add-in-found.html