ESMMOEIX A.I CyberSecurity Scoring
ESMMOEIX
Company Information
Website:https://www.xink.io/microsoft365/
Employees number:None
Number of followers:64
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:xink.io
ESMMOEIX Risk Score (AI oriented)
Between 750 and 799
ESMMOEIXIT Services and IT Consulting
Updated:
10/03/2026
10/03/2026
750/1000
Fair
Baa
ESMMOEIX Global Score (TPRM)
xxxx
ESMMOEIXIT Services and IT Consulting
Score locked

ESMMOEIXFair
Current Score
750Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
748
JULY 2025
748
JANUARY 2022
752
Cyber Attack
01 Jan 2022 • ESMMOEIX
Microsoft: Microsoft Outlook Add-In Stolen 4000 Accounts and Credit Card Numbers
Microsoft Outlook Add-In Hijacked to Steal Thousands of Credentials and Payment Data
730
CRITICAL-22
MIC1770890241
Microsoft Outlook Add-In Hijacked to Steal Thousands of Credentials and Payment Data
Security researchers at Koi Security uncovered a novel attack leveraging a dormant Microsoft Outlook add-in to harvest over 4,000 login credentials, credit card numbers, and banking security answers. The incident marks the first known malicious Office add-in discovered in the wild, exposing a critical flaw in Microsoft’s third-party tool distribution.
The attack centered on AgreeTo, a legitimate meeting-scheduling add-in published to the Microsoft Office Add-in Store in 2022. After the developer abandoned the project and its hosting domain expired, the subdomain (`outlook-one.vercel.app`) became available for registration. An attacker claimed the domain and replaced the original tool with a fake Microsoft sign-in page, which loaded inside Outlook via an iframe for all existing users.
Microsoft’s security review process only validates an add-in’s manifest file upon initial submission, meaning the malicious content change went undetected. The phishing page captured credentials and transmitted them to the attacker via a Telegram bot. Researchers accessed the exfiltration channel, recovering stolen data including Microsoft account logins, payment details, and IP addresses while the attackers were actively testing the credentials.
Though Microsoft removed the add-in from its store, the phishing infrastructure remained operational outside it. The AgreeTo manifest had ReadWriteItem permissions, granting potential access to read or modify users’ emails, though the attackers only deployed a basic phishing scheme. The incident underscores a broader vulnerability in software supply chains: Office add-ins function as remote dynamic dependencies, allowing content to change without Microsoft’s oversight.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for ESMMOEIX ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in May 2026 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in April 2026 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in March 2026 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in February 2026 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in January 2026 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in December 2025 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in November 2025 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in October 2025 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in September 2025 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in August 2025 ??
What was ESMMOEIX's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on ESMMOEIX's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with ESMMOEIX ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view ESMMOEIX's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?