The claim reviewed
Microsoft security teams observed a multi-stage campaign that targeted tens of thousands of users across 26 countries in April 2026. It used the pressure of an internal investigation to draw employees into a false process that ended at a system designed to capture session tokens.
Limits and uncertainty
This is a passive review. The domains are not tested and suspicious links are not opened. The sources are used only to understand the reporting language and the attack chain.

