Moneycontrol PRO
Loans
Loans
HomeTechnologyMicrosoft Outlook, Office 365 passwords leaked in a massive data breach

Microsoft Outlook, Office 365 passwords leaked in a massive data breach

Threat actors exploit link-wrapping services to launch phishing attacks and steal login credentials

August 04, 2025 / 19:18 IST

A new phishing campaign has raised concerns over the security of Microsoft Outlook and Office 365 accounts. Threat actors have been leveraging trusted link-wrapping services to distribute malicious URLs that redirect users to credential-harvesting pages, leading to the theft of Microsoft login information.

Abuse of trusted platforms

The attackers exploited email security tools from cybersecurity provider Proofpoint and cloud communications firm Intermedia between June and July. These platforms include link-wrapping features that rewrite URLs with trusted domains and scan them for malicious content. However, in this campaign, compromised accounts were used to wrap and send already malicious links, bypassing traditional email filters.

According to Cloudflare’s Email Security team, the attackers gained access to Proofpoint and Intermedia-protected email accounts and used them to send phishing emails containing “laundered” links. These links appeared legitimate due to the wrapping and redirection process.

“Attackers abused Proofpoint link wrapping in a variety of ways, including multi-tiered redirect abuse with URL shorteners via compromised accounts,” Cloudflare researchers explained. “The Intermedia link wrapping abuse we observed also focused on gaining unauthorized access to email accounts protected by link wrapping.”

Also read: Tools to check password breach

Fake Teams alerts and voicemail lures

The phishing emails often impersonated common business tools. Some messages mimicked Microsoft Teams notifications, claiming the recipient had received a new message. Others were disguised as voicemail alerts or secure message prompts. The links within these emails, once clicked, led to Microsoft 365 phishing pages designed to steal credentials.

In one observed tactic, the attackers used a shortened URL first, which was then automatically wrapped by a compromised account’s security platform. This multi-layered obfuscation helped bypass user suspicion and automated security tools.

Cloudflare Email SecuritySecurity implications

This campaign highlights a growing threat vector: abusing legitimate email security features to carry out phishing attacks. By hiding behind trusted domains and using real services like Constant Contact to host phishing pages, attackers were able to increase the success rate of their operations.

While it is unclear how many users were affected, the breach underscores the need for multi-factor authentication and regular monitoring of login activity. Enterprises using Microsoft Outlook and Office 365 should review email security configurations and educate users about advanced phishing tactics.

 

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Aug 4, 2025 07:13 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347