12,000 Inboxes Were Compromised Without Stealing a Password. The Victims Logged In on the Real Login Page
Takedown Good News, Real Lesson September 2026 · 8 min read The website was real. The password wasn't stolen. Multi-factor authentication worked exactly as designed. And the attacker still got in. This week, Microsoft disclosed and dismantled an AI-powered phishing operation that used exactly this technique to compromise more than 12,000 inboxes at over 10,000 organizations worldwide, since February. Here's how a real login page became part of the attack, and the one rule that stops it. For years, the first thing anyone learns about phishing is to check the address bar. Is this the real site? Is the certificate valid? Does the domain match? That instinct is correct, and it stops an enormous share of ordinary phishing. It's also, on its own, no longer a complete defense — because the technique behind this week's news doesn't need a fake website at all. ✓ The login page was genuine — the real Micr...