logo

The OAuth Phishing Trap: Proofpoint Exposes AiTM Attacks That Bypass MFA to Hijack Cloud Accounts

ID: 1b79e7a7-aa8f-5cc3-8be7-2750cda340b7

STIX ID: report--1b79e7a7-aa8f-5cc3-8be7-2750cda340b7

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2025-08-02

Date Updated: 2026-04-22

Author: Ddos

...
...

Proofpoint details widespread AiTM OAuth phishing campaigns that abuse maliciously registered Azure OAuth applications and the Tycoon PhaaS to proxy Microsoft 365 login flows, harvest credentials and MFA/session tokens, and achieve account takeovers; telemetry shows ~3,000 attempted compromises across ~900 tenants with a >50% observed success rate, and recommended defenses include blocking impersonation emails, detecting malicious OAuth apps, web isolation, user training, and adoption of phishing-resistant FIDO keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.