First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials

Feb 11, 2026

Cybersecurity researchers have discovered what they said is the first known malicious Microsoft Outlook add-in detected in the wild.
In this unusual supply chain attack detailed by Koi Security, an unknown attacker claimed the domain associated with a now-abandoned legitimate add-in to serve a fake Microsoft login page, stealing over 4,000 credentials in the process. The activity has been

Get Free Report & Network Analysis

Please check your email for the free report.