Skip to content
Brisbane, Queensland
wefixlogo

0477 319 160

  • Home
  • About Us
  • Services
  • Service Area
  • Blog
  • Contact Us

Tag: Outlook add-in

  • Home
  • Blog
  • Outlook add-in
13Feb 2026 by Admin No Comments
Malicious Outlook Add-In Infiltrates Microsoft Store, Compromises Thousands of Accounts

Malicious Outlook Add-In Infiltrates Microsoft Store, Compromises Thousands of Accounts

Cybersecurity & Privacy
A malicious Outlook add-in called AgreeToSteal bypassed Microsoft's vetting process and stole credentials from over 4,000 users through the official Office Store. The attacker hijacked an abandoned meeting scheduling tool by claiming its expired backend URL, then served a phishing kit through the trusted add-in without requiring Microsoft's re-approval. The compromised extension maintained a 4.71-star rating during harvesting passwords, credit card details, and banking information sent via Telegram's Bot API. Microsoft removed the add-in in February 2023, but the incident exposed critical vulnerabilities in how the company monitors live content changes versus initial submissions.A malicious Outlook add-in has slipped through Microsoft's vetting process and infiltrated the official Office Store, marking the first documented case of its kind. The compromised tool, codenamed AgreeToSteal by Koi Security researchers, exploited an abandoned legitimate…
Read More
0477 319 160
WordPress Theme - Totally by HashThemes
0477 319 160