I Need IT Support Now
Managed Service Provider - Cybersecurity
Shane

Hackers Disguise Malicious Login Pages as Microsoft OneNote to Steal Corporate Credentials

OneNote Phishing Campaign Targets Business Credentials Through Fake Login Pages – Three-Year Credential Harvesting Operation

Phishing Alert
That "Shared OneNote" Login Screen Might Be Stealing Your Password. And It Looks Perfect.

A phishing campaign running since 2022 fakes Microsoft OneNote sign-in pages to grab Office 365 credentials. Here is how to spot it.

TL;DR
Since January 2022, a phishing campaign has been faking Microsoft OneNote login pages to steal Office 365 and Outlook credentials, and researchers confirmed it was still active in April 2025. It starts with an email about a "shared document" or "audio note." The link leads to a convincing fake sign-in page - but it is hosted on a trusted platform like Notion, Glitch, or Google Docs, not a Microsoft domain, which helps it slip past filters. When you type your password, the page captures it (and your IP address) and ships it to the attackers over Telegram, then quietly redirects you to the real Microsoft login so you never notice. The two defenses that matter most: turn on multi-factor authentication everywhere, and check the web address before you ever enter a Microsoft password - a real sign-in always lives on a Microsoft domain.

Attackers are faking Microsoft OneNote login pages to steal Office 365 passwords - and hosting them on trusted services so your filters do not flag them.

This campaign is not new or flashy, and that is exactly why it works. It has run quietly since 2022 by keeping things simple: a believable email, a pixel-perfect fake login page on a service you already trust, and a quiet handoff back to the real Microsoft site so the theft goes unnoticed. Knowing the pattern is most of the defense.

The tell that never changes: a real Microsoft sign-in page lives on a Microsoft web address. If a "OneNote" login sits on a Notion, Glitch, or Google Docs link, it is not Microsoft.

What the Scam Is

A simple, durable credential-theft operation hiding behind trusted brands.

A fake OneNote login page captures your password and IP, sends them to attackers over Telegram, then redirects you to the real Microsoft site.

THE ONENOTE PHISHING FLOW 1 · THE LURE "Shared document" or "audio note" email 2 · FAKE LOGIN OneNote page on Notion / Glitch 3 · CREDS STOLEN Password + IP sent over Telegram 4 · COVER-UP Redirect to real Microsoft login
How the OneNote phishing scam works. Based on Cyber Security News reporting.

The pages present several sign-in options - Office 365, Outlook, and others - to look like a real Microsoft prompt. Because they are hosted on well-known platforms rather than a Microsoft domain, many email filters and reputation checks do not flag them. The campaign has mostly targeted small and midsize businesses in the U.S. and Italy.

Real vs. Fake: How to Tell

Four checks separate a genuine Microsoft sign-in from this fake.

The web address, the reason you got there, the post-login behavior, and the MFA prompt all give the fake away.

What to checkReal Microsoft sign-inThe OneNote fake
Web addressA Microsoft domain (for example, login.microsoftonline.com)A Notion, Glitch, or Google Docs URL - not Microsoft
Why you are thereYou chose to open an app and sign inAn unexpected email about a shared file or audio note
After you log inYou land in the app you openedYou are bounced to the real Microsoft page to hide the theft
MFAPrompts your genuine second factorNo real MFA - it just grabs the password

When in doubt, do not sign in from the link. Open a new browser tab, go to your Microsoft app directly, and check whether the document actually exists.

How to Protect Your Business

Two controls do most of the work; a few more close the gaps.

MFA plus link-analyzing email security defeats the core of this attack; training and monitoring handle the rest.

  • Turn on MFA everywhere. Even if a password is stolen, multi-factor authentication blocks the attacker from logging in.
  • Use email security that inspects links. Advanced filtering can follow and flag redirects to suspicious pages, even on trusted hosts.
  • Train the "check the address" habit. Teach staff that a real Microsoft login always lives on a Microsoft domain - and to verify unexpected share requests another way.
  • Verify senders out of band. Confirm surprise "shared document" emails with the sender by phone or chat before signing in.
  • Monitor for compromise. Watch for unusual logins and suspicious outbound traffic, and be ready to reset passwords fast.
  • Have a response plan. Rehearsed password-reset and account-audit steps shrink the damage of a stolen credential.
100% Free

Free Cybersecurity Assessment

Would a fake Microsoft login fool your team? Get a FREE review of your MFA, email security, and phishing defenses.

Get Your Free Assessment

The clever part of this scam is the redirect at the end - you type your password, then land on the real Microsoft page and assume everything worked. Nothing looks wrong, so nobody reports it. That is why MFA matters so much: it turns a stolen password into a dead end instead of an open door.
Shane Stevens, CEO, CinchOps - LinkedIn

Stop Credential Theft Before It Spreads

CinchOps protects Microsoft 365 accounts with MFA, link-analyzing email security, awareness training, and login monitoring - so a fake OneNote page never becomes a breach. It is part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, defending the Microsoft 365 logins attackers most want to steal.

  • MFA everywhere. Multi-factor authentication on every Microsoft 365 and business account.
  • Advanced email security. Link analysis that catches redirects to fake pages on trusted hosts.
  • Security awareness training. Phishing simulations and the "check the address" habit built into your team.
  • Login and threat monitoring. Alerting on unusual sign-ins and credential-theft indicators.
  • Incident response. Fast password resets and account audits to contain a stolen credential.

Do not let a perfect-looking login page cost you your business accounts. Contact CinchOps to lock down your Microsoft 365.

Frequently Asked Questions

What is the OneNote phishing scam?

It is a phishing campaign, active since January 2022, that fakes Microsoft OneNote login pages to steal Office 365 and Outlook credentials. Victims get an email about a shared document or audio note, click through to a convincing fake sign-in page hosted on a trusted platform, and have their password captured.

How do I tell a fake OneNote login from a real one?

Check the web address. A real Microsoft sign-in always lives on a Microsoft domain, while the fake pages are hosted on services like Notion, Glitch, or Google Docs. Also be suspicious of any login you reached from an unexpected "shared file" email.

Why do email filters miss these pages?

Because they are hosted on well-known, legitimate platforms rather than obviously malicious domains, many reputation-based filters do not flag them. That is exactly why the attackers use trusted services - and why link-analyzing email security and MFA matter.

What happens after my password is stolen?

The page sends your credentials and IP address to the attackers over Telegram, then redirects you to the genuine Microsoft login so nothing looks wrong. Victims often do not realize they were compromised until weeks later - which is why MFA and monitoring are essential.

What is the single best defense?

Multi-factor authentication. Even if attackers steal your password, MFA stops them from logging in. Pair it with the habit of checking the web address before entering any Microsoft credential.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506