Threat Intelligence|

How a phishing campaign moved from an email to session token theft

A Microsoft report shows that modern credential phishing is no longer limited to a fake sign-in page. This file examines how a code-of-conduct email, a document attachment, and several redirect steps formed one social engineering chain.

The claim reviewed

Microsoft security teams observed a multi-stage campaign that targeted tens of thousands of users across 26 countries in April 2026. It used the pressure of an internal investigation to draw employees into a false process that ended at a system designed to capture session tokens.

Limits and uncertainty

This is a passive review. The domains are not tested and suspicious links are not opened. The sources are used only to understand the reporting language and the attack chain.


Sources

Related files