Microsoft Store Outlook Add-In Exploited in Major Credential Heist Impacting Thousands
A hijacked Outlook add-in available through Microsoft’s official store compromised over 4,000 user credentials through an elaborate phishing scheme that exploited a fundamental architectural flaw security researchers have warned about since 2019. The AgreeTo add-in, originally a legitimate meeting scheduling tool with 4.71-star ratings, was abandoned by its developer in late 2022, allowing threat actors to hijack its expired Vercel-hosted URL and transform the trusted add-in into a credential harvesting machine operating directly within Outlook’s sidebar, complete with Telegram-based command-and-control infrastructure that collected passwords, IP addresses, and even credit card details before redirecting victims to legitimate Microsoft login pages to mask the breach—a supply-chain vulnerability that persists across Microsoft’s add-in ecosystem as a result of absent URL verification and code review processes, raising questions about what other dormant threats lurk in the store awaiting exploitation.
When a developer walks away from a project, the code doesn’t always follow them into retirement—sometimes it becomes a weapon. Over 4,000 Microsoft account credentials were stolen through a hijacked Outlook add-in that sat in the Microsoft Store with a respectable 4.71-star rating, exploiting a security blind spot that shouldn’t exist in 2025.
Over 4,000 credentials stolen through a legitimate-looking Outlook add-in that Microsoft vouched for exactly once, then never verified again.
The AgreeTo add-in started life legitimately enough. Launched in December 2022 as a meeting scheduling tool by an independent researcher, it offered a Chrome extension counterpart and earned solid user reviews. But when its developer abandoned the project, the Vercel-hosted URL powering the add-in expired. That’s when someone with considerably less noble intentions stepped in.
A threat actor claimed the orphaned outlook-one.vercel.app subdomain and transformed it into a credential harvesting operation. Here’s the clever part: they didn’t need to submit anything new to Microsoft. The original manifest—already approved, reviewed, and signed by Microsoft—granted ReadWriteItem permissions, allowing the add-in to read and modify emails. Microsoft’s review process examines initial submissions but conducts no ongoing verification of the URLs those add-ins load.
The phishing kit was straightforward but effective. Four pages comprising a fake Microsoft login screen, password collection form, exfiltration script, and redirect page appeared directly in Outlook’s sidebar. It looked legitimate since it existed within a Microsoft-approved container. Victims entered credentials that were immediately sent to the attacker via Telegram bot API along with their IP addresses, then redirected to the real login.microsoftonline.com to avoid suspicion.
But usernames and passwords weren’t the only prizes. Credit card numbers, CVVs, PINs, and banking security answers for Interac e-Transfer interception were likewise collected. Researchers from Koi, who discovered the operation, watched the attacker actively testing stolen credentials during their examination. They’d gained access to the exfiltration channel itself.
This wasn’t amateur hour. The operator runs at least 12 additional phishing kits targeting Canadian ISPs, banks, and webmail providers—a professional multi-brand operation using Telegram bots to bypass traditional command-and-control infrastructure.
Microsoft removed the add-in the same day Koi reported it, but the architectural flaw remains. The company’s add-in model presents supply-chain risks that won’t vanish with one takedown. No code review exists in the submission process, and in some scenarios, no audit logs track what add-ins actually do once installed. This marks the first documented case of malware hosted on the Microsoft Marketplace itself. Security researchers had previously warned about this vulnerability as early as 2019.
The contrast with Google is telling. Whilst Google removed AgreeTo’s Chrome extension in February 2025, Microsoft’s version remained available until researchers flagged it.
For users caught in this operation, the damage extends beyond password resets. Financial monitoring and vigilance against potential email exfiltration are now necessary precautions. Your inbox, it turns out, trusted something Microsoft vouched for exactly once.
Final Thoughts
The Outlook add-in breach demonstrates that enterprise security vulnerabilities often stem from inadequately vetted extensions, with Microsoft needing to enhance its app store vetting processes and implement runtime monitoring for applications with mailbox access. Organizations must immediately audit their installed add-ins and deploy multi-factor authentication across all systems, as attackers will continue exploiting legitimate distribution channels for credential theft.
Zoo Computer Repairs specializes in comprehensive security audits, add-in management, multi-factor authentication implementation, and enterprise email security hardening to protect businesses from sophisticated attacks like this Outlook add-in exploit. Our cybersecurity experts can assess your current vulnerabilities, remove malicious extensions, and establish robust security protocols to prevent credential theft.
Don’t wait for the next security breach to impact your business. Contact us today to schedule a complete security assessment and protect your organization from email-based attacks and malicious add-ins.
