Microsoft flags major ‘sophisticated’ phishing campaign targeting 35,000 users across 26 countries
AI-summarised brief · reviewed before publication
Microsoft has flagged a sophisticated phishing campaign targeting 35,000 users across 26 countries, with 92% of emails sent to US-based organizations. The campaign, observed between April 14 and 16, 2026, used polished HTML templates and assumed different identities to create a sense of urgency and pressure to act. Healthcare and life sciences firms were most affected, followed by financial services and technology companies.
💡 Why It Matters
- · By bypassing traditional protections and using legitimate services, the attackers have exposed a significant vulnerability in current security measures.
- · The campaign's ability to harvest Microsoft credentials and tokens in real-time also undermines the effectiveness of multi-factor authentication.