A popular Microsoft Outlook add-in has been hijacked in an attempt to steal user accounts – here’s how to stay safe



  • Abandoned Outlook AgreeTo add-on hijacked in phishing kit that steals Microsoft accounts
  • The attackers stole 4,000 accounts, credit card data and bank security responses.
  • Microsoft removed the plugin; Users are urged to reset passwords and monitor financial activity.

Experts warned that hackers took over a legitimate but abandoned add-in project for Microsoft Outlook and turned it into a full-fledged phishing kit.

Security researchers Koi said they discovered AgreeTo, an Outlook add-on meeting scheduler with a relatively large user base on the email provider.



Leave a Comment

Your email address will not be published. Required fields are marked *