Agree.com A.I CyberSecurity Scoring
Agree.com
Company Information
Website:https://agree.com/
Employees number:14
Number of followers:5,534
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:agree.com
Agree.com Risk Score (AI oriented)
Between 700 and 749
Agree.comTechnology, Information and Internet
Updated:
28/02/2026
28/02/2026
746/1000
Moderate
Ba
Agree.com Global Score (TPRM)
xxxx
Agree.comTechnology, Information and Internet
Score locked

Agree.comModerate
Current Score
746Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
747
MAY 2026
747
APRIL 2026
746
MARCH 2026
746
FEBRUARY 2026
764
Vulnerability
11 Feb 2026 • Agree.com
AgreeTo: Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts
Malicious AgreeTo Outlook Add-In Hijacked to Steal 4,000 Microsoft Credentials
746
CRITICAL-18
AGR1770850632
Malicious AgreeTo Outlook Add-In Hijacked to Steal 4,000 Microsoft Credentials
A legitimate Outlook add-in, AgreeTo, was hijacked by threat actors and repurposed as a phishing kit, resulting in the theft of over 4,000 Microsoft account credentials, along with credit card details and banking security answers. Originally developed as a meeting scheduling tool, the add-in was published on Microsoft’s Office Add-in Store in December 2022 by an independent developer who later abandoned the project leaving its Vercel-hosted URL (outlook-one.vercel.app) vulnerable to takeover.
Researchers at supply-chain security firm Koi Security discovered that the abandoned URL was claimed by a threat actor, who replaced the add-in’s legitimate content with a fake Microsoft sign-in page, a credential harvesting script, and an exfiltration mechanism. Once installed, the malicious add-in displayed a convincing phishing prompt in Outlook’s sidebar, tricking users into entering their credentials. Stolen data was transmitted via a Telegram bot API before victims were redirected to the real Microsoft login page to avoid suspicion.
The add-in retained ReadWriteItem permissions, allowing it to access and modify user emails, though no such activity was confirmed. Koi Security found that the attacker operates multiple phishing kits targeting ISPs, banks, and webmail providers. The compromised AgreeTo add-in remained available on Microsoft’s store until its removal on the day of disclosure.
This incident marks the first known case of malware distributed via Microsoft’s official Marketplace and the first malicious Outlook add-in detected in the wild. Microsoft’s review process for add-ins limited to initial manifest verification failed to detect the compromise, as the malicious content was loaded from the attacker-controlled server. No official response from Microsoft has been issued at this time.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
764
DECEMBER 2025
764
NOVEMBER 2025
764
OCTOBER 2025
764
SEPTEMBER 2025
764
AUGUST 2025
764
JULY 2025
764
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Agree.com ??
What was Agree.com's A.I Rankiteo Cyber Score in May 2026 ??
What was Agree.com's A.I Rankiteo Cyber Score in April 2026 ??
What was Agree.com's A.I Rankiteo Cyber Score in March 2026 ??
What was Agree.com's A.I Rankiteo Cyber Score in February 2026 ??
What was Agree.com's A.I Rankiteo Cyber Score in January 2026 ??
What was Agree.com's A.I Rankiteo Cyber Score in December 2025 ??
What was Agree.com's A.I Rankiteo Cyber Score in November 2025 ??
What was Agree.com's A.I Rankiteo Cyber Score in October 2025 ??
What was Agree.com's A.I Rankiteo Cyber Score in September 2025 ??
What was Agree.com's A.I Rankiteo Cyber Score in August 2025 ??
What was Agree.com's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Agree.com's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Agree.com ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Agree.com's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?