Office 365 Phishing Attacks: How Open Redirects Are Being Used to Steal Credentials
Â
Is your organisation protected against the latest Microsoft 365 phishing threats?
Cybercriminals are getting more sophisticated, using trusted domains and technical tricks to make phishing emails appear legitimate, especially when targeting Office 365 credentials.
One of the latest phishing techniques involves the abuse of open redirects, what once was a legitimate web development feature that’s now being exploited to deceive users and security filters alike.
Â
What Is an Open Redirect and Why Is It Dangerous?
An open redirect is a URL that automatically sends users from a known, trusted domain to a different destination. For example:
https://example.com/redirect.php?url=http://attacker.com
Cyber attackers use this technique to disguise malicious links, making it harder for users and email security tools to detect threats. In many cases, these phishing campaigns use familiar services like Google reCAPTCHA to create an additional layer of credibility and further hide the final malicious destination.
Â
How Phishing Attacks Are Targeting Microsoft 365 Users
According to Microsoft security analysts, attackers are:
- Embedding phishing URLs inside legitimate-looking links
- Using open redirects to bypass traditional email security filters
- Adding intermediary steps (e.g., reCAPTCHA pages) to mask final malicious pages
- Mimicking login pages to steal Office 365 usernames and passwords
These tactics are making it harder for employees to detect phishing scams, even when they hover over links before clicking.
Â
Why Security Awareness Training Is Essential
While hovering over links remains a useful habit, it’s no longer enough. Businesses must go further by:
- Implementing comprehensive cybersecurity awareness training
- Educating employees on the latest phishing tactics
- Encouraging scepticism toward unsolicited emails, even those from trusted sources
- Providing real-world examples during training sessions
Â
Is Your Team Prepared for Office 365 Phishing Attacks?
Don’t wait until your Microsoft 365 environment is compromised; train your team today to stop phishing threats tomorrow.
👉 Need Help with an IT Project or Issue?
Talk to a Cybersecurity Specialist Today
Protect your identity and business from emerging cyber-threats.
Not sure how this impacts you?
We're ready to help!
Chat to one of our friendly experts today.


