Phish of the Week
August 17, 2026

Phish of the Week 17th of August

Phish of the Week 17th of August
# Phish of the Week
# Phishing

Project Collaboration Invite

Mette Luntama
Mette Luntama
Phish of the Week 17th of August

Phish of the Week: Fake Project Collaboration Invite Impersonates Microsoft Teams With a Simulated Live Meeting

This attack impersonates a business collaboration invite that funnels targets through a fake e-signature approval page and a simulated Microsoft Teams meeting to harvest Microsoft credentials. What makes this campaign especially interesting is its use of an audio message to reinforce the authenticity of the fake Teams meeting, a sensory detail static credential pages rarely include.

How the attack works:

The email arrives from a look-alike address styled to resemble an impersonated company, complete with that company's real logo in the signature. The text states that the sender has cc'd themselves "to keep things running smoothly," a detail that in reality masks the fact that the message's To and From addresses are set to the same look-alike addresses, since the actual recipient was likely bcc'd along with many other targets. The email references an approved project number and explains that, per company policy, a meeting must be scheduled before project requirements are shared and an NDA is signed.

Clicking the embedded "Schedule a Meeting" link opens a page styled to look like Adobe Acrobat Sign. Despite copying Adobe's branding closely, the page contains a spelling error in its own heading, rendering "Invitation" as "Inviatation."
From there, a page branded as Microsoft Teams asks the recipient to enter their name and email to register for the meeting, information the attack immediately reuses in the next step.

The next screen is a simulated Teams meeting lobby, personalized with initials generated from the name just entered and populated with two fake participant tiles labeled "Purchase Manager" and "Project Manager" to suggest a meeting already underway. Clicking "Join Meeting" plays a recorded greeting, "Good morning our honorable speaker and delegates as we start our meeting," reinforcing the impression that the target has joined a live call in progress.
The recording is immediately followed by a Microsoft-branded login page requesting a password. Once submitted, a second Microsoft login prompt appears, framed as re-verifying the password "because you're accessing sensitive info." Only after this second entry does the attack conclude, having requested the credential twice to increase the odds it was captured correctly.



Why the attack works:

Mundane lure: The initial email itself is unremarkable. Business collaboration requests routinely arrive by email at most companies, so nothing about receiving this message reads as out of place.
Covering its own tracks: The identical sender and recipient address, an oddity a more careful reader might otherwise notice, is pre-empted by the self-cc line. It offers a plausible, mundane explanation before the recipient has any reason to question it.
Convincing, and urgent, landing page: The simulated Teams meeting lobby is more convincing than a typical static, audio-less credential harvesting page, and it introduces a kind of urgency the email itself never did: the impression that a meeting is already underway and the recipient needs to join immediately, right as the login prompt appears.


How to spot similar attacks:

  • Unsolicited email referencing an approved project or collaboration with no established business relationship
  • The "To" address in the email header matches the sender's own address, a sign the message may be bcc'd to many recipients rather than sent individually
  • A request to schedule a meeting or sign an NDA before any project details are shared
  • Generic link text such as "Schedule a Meeting" that gives no indication of its actual destination
  • Spelling errors on linked pages, even when the overall branding looks convincing


What is Phish of the Week?

Phish of the Week is a weekly content initiative by Hoxhunt's Threat Operations team. Each week, we highlight a current phishing trend or notable real-world attack, covering what the threat is, how it works, and what to watch for to spot similar attacks in the future. The goal is to build consistent recognition of evolving phishing themes and tactics over time.
Comments (0)
Popular
avatar

Dive in

Related

Content
Phish of the Week 24th of August
By Mette Luntama • Aug 24th, 2026 Views 5
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 13
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 03rd of August
By Mette Luntama • Aug 3rd, 2026 Views 8
Content
Phish of the Week 24th of August
By Mette Luntama • Aug 24th, 2026 Views 5
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 03rd of August
By Mette Luntama • Aug 3rd, 2026 Views 8
Content
Phish of the Week 27th of July
By Mette Luntama • Jul 27th, 2026 Views 13