Microsoft’s Defender Research team reports a large-scale phishing campaign that uses fake “workplace compliance” notices to trick people into entering credentials on fraudulent sign-in pages. According to Microsoft, the campaign targets Microsoft account owners and is designed to move recipients from an email inbox to an attempted account takeover by collecting login information during the fake sign-in process.
The campaign reaches more than 35,000 users across about 13,000 organizations in 26 countries, with a heavier concentration of targets in the United States, though victims are reported internationally. Microsoft does not provide an estimate of how many recipients were successfully compromised or how many accounts were actually taken over.
Both outlets describe the same overall theme: the phishing emails impersonate compliance-related workplace communications, and the primary goal is credential theft rather than a direct distribution of malware. Microsoft’s warning highlights the scale of the attempt and the breadth of organizations affected, while leaving open the number of successful compromises.