A popular Microsoft Outlook add-in has been hijacked to try and steal user accounts – here’s how to stay safe



  • Abandoned Outlook add-in AgreeTo hijacked into phishing kit stealing Microsoft accounts
  • Attackers stole 4,000 accounts, credit card data, and banking security answers
  • Microsoft removed add-in; users urged to reset passwords and monitor financial activity

Hackers took over a legitimate, but abandoned, add-in project for Microsoft Outlook and turned it into a full-blown phishing kit, experts have warned.

Security researchers Koi said they discovered AgreeTo, an Outlook add-on meeting scheduler with a relatively large user base on the email provider.


https://cdn.mos.cms.futurecdn.net/TLZcsEGFPY2WCSSbjPXEqQ-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img