logo

Microsoft warns of global campaign stealing auth tokens from 35K users

ID: 3b5e9c11-8a92-510f-a4a5-34ca42c16eda

STIX ID: report--3b5e9c11-8a92-510f-a4a5-34ca42c16eda

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Pierluigi Paganini

...
...

Microsoft disclosed a sophisticated phishing campaign in mid‑April 2026 that targeted over 35,000 users in 26 countries using polished “code of conduct” lures delivered via legitimate services; the attackers led victims through CAPTCHAs and staged pages to an AiTM sign‑in proxy that captured authentication tokens and bypassed MFA, primarily affecting U.S. healthcare and finance organizations and prompting recommendations for layered anti‑phishing defenses and stronger authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.