HomeSecurityMicrosoft 365: Outlook add-ins abused to steal email data

Microsoft 365: Outlook add-ins abused to steal email data

A serious architectural flaw in the Microsoft 365 is exposing new risks to corporate communications. According to recent research, threat actors can extract sensitive email data with virtually no digital footprint, bypassing even advanced logging and auditing mechanisms.

Microsoft 365 Outlook

The technique, dubbed “Exfil Out&Look,” exploits legitimate features of Outlook add-ins, turning a productivity tool into a silent data-sniffing.

How the Exfil Out&Look attack works

Unlike traditional cyberattacks based on exploits or malware, Exfil Out&Look does not require code cracking or zero-day exploits. Instead, it abuses perfectly legitimate features of Outlook Web Access (OWA).

See also: CISA chief uploaded sensitive files to ChatGPT

Outlook add-ins are applications based on web technologies — HTML, CSS, and JavaScript — and operate through a manifest file in XML format, which specifies permissions and integration points into the Office environment.

The Varonis research team demonstrated that an attacker can create a malicious add-in that exploits the OnMessageSend event , a function normally intended for checking or processing emails before sending them.

Minimum permissions, maximum access

The crucial element of the technique is that the add-in only needs the ReadWriteItem. With this, it gains access to:

  • in the subject line
  • in the body of the email
  • to the recipients
  • in the attached metadata

This level does not activate mechanisms to warn users or administrators, so the installation can go unnoticed.

Once the user presses "Send", the malicious JavaScript code runs in the background and transmits the data to an external server via a simple fetch()call, without any visible impact on Outlook's operation.

See also: Criminals seize and resell AI infrastructure

Microsoft 365: Outlook add-ins abused to steal email data

The dangerous loophole in logs

The most concerning finding concerns the difference in behavior between Outlook Desktop and Outlook Web Access.

When an add-in is installed on the desktop client, a log is created in the Windows Event Viewer (Event ID 45), providing valuable information.

However, when the same process is performed via OWA:

  • not recorded in the Microsoft 365 Unified Audit Log
  • does not appear in security alerts
  • does not create a visible trace of activity

Even in Microsoft 365 E5 with full auditing enabled, the installation and execution of the add-on remains virtually invisible.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This creates an extremely dangerous scenario, where an attacker — either an external one with a compromised account or a malicious internal user — can install an email extraction mechanism that operates indefinitely.

Why security tools don't detect it

Although outgoing network traffic can theoretically be seen in firewalls or proxy systems, there is no internal correlation within the Microsoft 365 tenant to indicate that:

  • email content was accessed
  • there was a data export
  • plugin was executed at the time of sending

Simply put, the data is gone, but the Microsoft 365 environment doesn't know who exported it, when, and why.

See also: Fake Moltbot AI coding assistant on VS Code Marketplace

Microsoft's reaction

Varonis shared the findings with the Microsoft Security Response Center (MSRC) on September 30, 2025. After assessment, Microsoft classified the issue as a low severity design issue, with no immediate plan to fix or change the code.

This means that the Exfil Out&Look technique remains an active and operational data theft vector, posing a particular threat to organizations that rely exclusively on the platform's built-in logs.

Microsoft 365: Outlook add-ins abused to steal email data

What should organizations do?

Experts emphasize that defense can no longer rely solely on incident recording. Preventive governance.

Key recommendations include:

  • ban on installing add-ons by end users
  • use allow-list exclusively through the Microsoft 365 Admin Center
  • continuous Azure AD monitoring for suspicious application registrations
  • monitoring creation of service principals that do not correspond to known applications
  • periodic checks of Outlook add-ins across the organization

In many cases, the existence of an unknown application registration in Azure Active Directory may be the only clue that a malicious add-on has been deployed.

See also: eScan: Compromised update server pushed malicious update

Microsoft 365: Outlook add-ins abused to steal email data

A bell for the future of cloud security

The Exfil Out&Look case highlights a critical problem in modern cybersecurity: as cloud platforms become more feature-rich, so do the points of abuse.

This is not a code error, but a conflict between functionality and visibility. And in this gap, attackers find space to operate silently.

For businesses, the message is clear: security in Microsoft 365 depends not only on E5 licenses and default logs, but on the right policy, permission restrictions, and constant monitoring — before emails become the most invisible data leakage point.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS