In the continuously evolving landscape of cyber threats, a new type of attack has targeted Microsoft Outlook users. For the first time, a malicious add-in officially available in the Microsoft store has been identified, highlighting how cybercriminals are developing increasingly sophisticated methods to steal sensitive information.
Cybersecurity company Koi Security discovered an Outlook add-in called “AgreeTo” (code name “AgreeToSteal”) that was used to steal over 4,000 Microsoft credentials. The attack mechanism is particularly insidious: the add-in exploited an abandoned domain (outlook-one.vercel.app) to host a counterfeit Microsoft login page. When users interacted with the add-in, they were directed to this fake page where they entered their credentials, which were then stolen by the attackers in what is classified as a supply chain attack. Despite the add-in being last updated in December 2022, it was still available in the Microsoft store as of February 2026.
This incident is particularly significant as it represents the first documented case of a malicious Outlook add-in that passed Microsoft’s security checks. The implications are concerning: stolen credentials could be used to access corporate emails, sensitive data, and potentially other connected services, creating significant risks for personal and corporate security. Furthermore, this case highlights the vulnerability of the software supply chain, where even seemingly legitimate tools can hide harmful functionalities.
To protect against similar threats, companies and users should adopt some fundamental precautions. It is advisable to carefully verify each add-in before installation, checking reviews, the developer’s reputation, and required permissions. Enabling two-factor authentication can provide an additional layer of protection even in case of credential theft. Additionally, organizations should implement monitoring systems to identify suspicious behaviors in their email systems and regularly train staff on recognizing phishing threats.
- Key points to remember:
- For the first time, a malicious add-in for Microsoft Outlook has been discovered that stole over 4,000 credentials through a counterfeit login page.
- The “AgreeTo” add-in remained available in the Microsoft store for years, demonstrating that even official channels can contain harmful software.
- Protection requires continuous vigilance: always verify the legitimacy of add-ins, implement two-factor authentication, and stay updated on emerging threats.
Sources:
https://thehackernews.com/2026/02/first-malicious-outlook-add-in-found.html
https://www.wiu.edu/cybersecuritycenter/cybernews.php
https://gbhackers.com/microsoft-outlook-add-in-stolen-4000-accounts/
Source: The Hacker News