Abandoned Outlook add-in hijacked through an expired subdomain
The Outlook add-in AgreeTo, an open-source meeting scheduling tool, was taken over by an attacker and used to steal credentials, card numbers and answers to banking security questions. The tool was published in 2022, last updated in May 2023 and then apparently abandoned by its developer. The takeover did not come through malicious dependencies or stolen developer credentials, but through an expired subdomain the add-in relied on. The attacker claimed that subdomain and could deliver a phishing kit to thousands of users without changing a line of the published add-in.
What this means for your organisation
Outlook and Microsoft 365 add-ins are typically approved once and never looked at again. This case shows an add-in can turn hostile long after approval, with nothing in the add-in itself changing. Approval at procurement is therefore not enough; only ongoing review catches the moment a supplier stops maintaining a tool.
Berigo recommends
- Review which Outlook and Microsoft 365 add-ins are approved in your tenant and remove the ones nobody actually uses.
- Check when each remaining add-in was last updated, and treat anything unmaintained for two years as a risk.
- Verify which external domains the add-ins load content from, and whether those domains are still controlled by the supplier.
- Put a fixed annual review of approved add-ins into your supplier follow-up routine.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch