logo

Microsoft 365 accounts targeted in wave of OAuth phishing attacks

ID: f141b3b8-86ae-5e02-bc63-971dbf3d5c5c

STIX ID: report--f141b3b8-86ae-5e02-bc63-971dbf3d5c5c

Feed Name: Proofpoint Blog

Threat Score
78/100

Date Published: 2025-12-19

Date Updated: 2026-04-28

...
...

Proofpoint reports a surge in OAuth device-code phishing attacks targeting Microsoft 365 accounts where users are lured to enter device codes on Microsoft’s legitimate device login page, unknowingly granting attacker-controlled applications access and enabling account takeover without credential theft or MFA bypass; campaigns use phishing kits like SquarePhish and Graphish and involve financially motivated and state-aligned actors (e.g., TA2723 and UNK_AcademicFlare), primarily targeting government, academic, think-tank, and transportation sectors, with recommendations to apply Microsoft Entra Conditional Access and sign-in origin policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.