logo

Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA

ID: 43b73db9-5941-55ce-ade7-153feab0a8fb

STIX ID: report--43b73db9-5941-55ce-ade7-153feab0a8fb

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Labs observed an active North America-focused phishing campaign (first seen December 2025) that tricks victims into entering attacker-supplied device codes at the legitimate Microsoft device login portal, enabling real-time theft of OAuth access and refresh tokens and effectively bypassing passwords and MFA. The report outlines a five-phase attack flow, examples of social-engineering lures, IOCs (malicious senders, domains, cloud storage URLs, subject patterns), and immediate/strategic mitigations including blocking IOCs, auditing OAuth app consent, reviewing Azure AD sign-in logs, and disabling the device code flow via Conditional Access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.