A popular Microsoft Outlook add-in has been hijacked to try and steal user accounts – here’s how to stay safe


  • Abandoned Outlook add-in AgreeTo hijacked in phishing kit that steals Microsoft accounts
  • Attackers stole 4,000 accounts, credit card data and bank security answers
  • Microsoft removed the add-on; users are encouraged to reset passwords and monitor financial activity

Hackers took over a legitimate but abandoned Microsoft Outlook add-in project and turned it into a full-fledged phishing kit, experts have warned.

Security researchers Koi said they discovered AgreeTo, a meeting scheduling Outlook add-in with a relatively large user base on the email provider.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top