Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Security

Phishing keeps getting smarter: Microsoft and Google abused

21 January 2026·Trung Nguyêñ Dúc, Head of Technology
Phishing keeps getting smarter: Microsoft and Google abused

Microsoft is once again the most imitated brand in phishing attacks. According to Check Point Research, 22 percent of all brand phishing in the fourth quarter of 2025 targeted Microsoft, followed by Google (13 percent) and Amazon (9 percent); Facebook returned to the top ten. The fake messages and login pages are deceptively real, and increasingly made with AI.

Phishing-resistant MFA — two-step verification that cannot be intercepted or relayed, such as passkeys or FIDO2 keys. An SMS or app code can be read along live by an attacker; a passkey only works on the genuine website.

Why Microsoft and Google in particular

These brands sit at the heart of identity and collaboration: whoever has an employee's Microsoft 365 or Google password has mail, files and often access to other systems. Because we use these brands every day, we click almost automatically on "your password is expiring" or "a document has been shared with you".

Why it works so well

Three things make modern phishing dangerous. Trust: a familiar logo lowers the threshold. Urgency: "your account will be blocked" puts people under pressure. And technology: with AI, texts are flawless and personal, and with adversary-in-the-middle attacks criminals intercept the login session after a successful MFA prompt. The attacker literally sits between you and the real login page.

What you can do now

  • Phishing-resistant MFA: passkeys or FIDO2 keys instead of SMS codes.
  • Conditional Access: access only from managed devices and trusted locations.
  • Awareness training with simulated phishing, so the team learns to recognise the signals.
  • E-mail security that stops malicious messages before they reach the inbox.
  • A report button in Outlook, so suspicious mail reaches IT in one click.

Qteco's approach

We combine these measures into one whole: hard technical barriers, continuous training and 24/7 monitoring that immediately picks up abnormal login behaviour, for example a sign-in from another country within an hour of a successful login in Eindhoven. The strongest defence against smart phishing is an environment that thinks along, and a team that knows what to look for.

Frequently asked questions

How do I recognise a fake Microsoft e-mail?

Look at the sender domain, not the display name; hover over the link and check whether it goes to microsoft.com or your own tenant; distrust urgency. In doubt? Do not go through the e-mail but straight to portal.office.com.

Is MFA with the Authenticator app not enough?

It is far better than nothing and stops most attacks. Against adversary-in-the-middle it does not help: the code is relayed live. For administrators and finance roles, passkeys or hardware keys are the standard.

How often should awareness training recur?

Short and regular works better than one annual session: a simulation every quarter and a brief explanation of each new attack type keep the signals sharp.

Want to know where your organisation stands? Take the free Microsoft 365 security check or read how managed cybersecurity combines these layers.

Sources

  1. Microsoft Remains the Most Imitated Brand in Phishing Attacks in Q4 2025 — Check Point Research
  2. Report: Microsoft Was the Most Impersonated Brand in Q4 2025 — KnowBe4

Read also

Firewalls and VPNs under fire: how to keep the door shut

NCSC warns: critical WordPress flaw actively exploited

Citrix NetScaler exploited before a patch existed

Ready to run worry-free?

Book a no-obligation introduction. We map your IT and security and show where the difference lies.

Book a call →