Phish of the Week
August 3, 2026

Phish of the Week 03rd of August

Phish of the Week 03rd of August
# Phish of the Week
# Phishing

Team Lunch Invite – OAuth Link Redirection

Mette Luntama
Mette Luntama
Phish of the Week 03rd of August

Phish of the Week: Team Lunch Invitation Abuses Microsoft OAuth to Deliver a Google Credential Harvester

This week's Phish of the Week breaks down a team lunch RSVP email that uses a real Microsoft sign-in link to hand recipients off to a fake Google credential harvester.

How the attack works:

The recipient receives an email inviting them to RSVP to a team lunch by clicking through to a shared spreadsheet. The email and the sender address are personalized with the recipient's company name, but the sender domain has no real connection to that company.

Clicking the "Open" button leads to a Microsoft OAuth authorize request at login.microsoftonline.com, a genuine Microsoft endpoint. The link points to an application the attacker registered themselves, so while the domain is real, the destination Microsoft ultimately sends the browser to is entirely under the attacker's control and invisible to the recipient at the point of clicking.
In this case, the destination turns out to have nothing to do with Microsoft at all.

The redirect lands the recipient on an unpolished, Google-branded page showing a malicious URL in the address bar. The page displays a fake "verifying secure connection" animation before presenting what looks like a standard Google sign-in form. Entering credentials there sends them directly to the attacker.

Why the attack works:

The first factor working in the attacker's favor is the lure itself, chosen to lower guard rather than raise it. A team lunch RSVP has no deadline, no financial stakes, and no authority behind it, so it doesn't trigger the same caution a request from "finance" or "IT" might. Personalizing the email address and content with the recipient's real company name reinforces the sense that this is an internal, routine message, even though the sender domain actually has no real connection to that company.
The second factor is the malicious redirect. Even a recipient who does habitually check a link before clicking finds nothing wrong here. Hovering over the "Open" button shows a genuine login.microsoftonline.com address, because the malicious hand-off happens after Microsoft processes the sign-in request, not in the link itself. There's no altered domain or misspelled brand name to catch at a glance.
The third element helping the attack blend is the jump from a Microsoft sign-in to what looks like a Google-hosted spreadsheet, which isn't unusual on its own. Employees at organizations using Google Workspace may routinely cross between different providers' login screens to reach shared documents, and few people are aware that a legitimate Microsoft OAuth link can be configured by an attacker to redirect elsewhere.


How to spot similar attacks:

  • The sender address does not match the organization it claims to be from
  • An internal team lunch or social event RSVP is delivered as an external link rather than a native calendar invite
  • A single link is presented as the only way to view or respond to a "shared" document, with no alternative in-app access
  • A sign-in flow shifts from one recognizable provider to an entirely different one partway through, without explanation
Rather than clicking a link in an unexpected invitation, navigate directly to your company's calendar or spreadsheet tool through a trusted route, and confirm the invite in person or through another internal channel, such as Slack or Teams, before treating it as real.


What is Phish of the Week?

Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.
Comments (0)
Popular
avatar

Dive in

Related

Content
Phish of the Week 24th of August
By Mette Luntama • Aug 24th, 2026 Views 5
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 13
Content
Phish of the Week 17th of August
By Mette Luntama • Aug 17th, 2026 Views 16
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 24th of August
By Mette Luntama • Aug 24th, 2026 Views 5
Content
Phish of the Week 17th of August
By Mette Luntama • Aug 17th, 2026 Views 16
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 13