Microsoft 365 phishing kit steals accounts for $320/month

Published August 26, 2026

A phishing service lets attackers steal Microsoft 365 accounts for $320 a month. It tricks users into entering their login details on fake Microsoft pages.

Report priority
Medium
Targets
Microsoft 365

How it works

  • Attackers rent a phishing kit that sends fake Microsoft 365 login emails.
  • When users click the link, they land on a fake Microsoft page that steals their email and password.

What to do

If you got a fake Microsoft 365 email asking you to update your account, never click links in unsolicited Microsoft emails.

Use Microsoft's official login page or check the email address in the sender's info.

Technical details

A user gets an email that looks like it's from Microsoft. It says their account needs updating. When they click the link, they're taken to a fake Microsoft login page. They type in their email and password, but it goes to the attacker instead. The attacker now has their Microsoft 365 account.

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.