Microsoft warns of global campaign stealing auth tokens from 35K users
ID: 3b5e9c11-8a92-510f-a4a5-34ca42c16eda
STIX ID: report--3b5e9c11-8a92-510f-a4a5-34ca42c16eda
Feed Name: Security Affairs
Microsoft disclosed a sophisticated phishing campaign in mid‑April 2026 that targeted over 35,000 users in 26 countries using polished “code of conduct” lures delivered via legitimate services; the attackers led victims through CAPTCHAs and staged pages to an AiTM sign‑in proxy that captured authentication tokens and bypassed MFA, primarily affecting U.S. healthcare and finance organizations and prompting recommendations for layered anti‑phishing defenses and stronger authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
