logo

Attackers Target Education Sector, Hijack Microsoft Accounts

ID: ed5f5600-3070-5ef6-a33b-425fdb992139

STIX ID: report--ed5f5600-3070-5ef6-a33b-425fdb992139

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-02-05

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers from Abnormal Security observed an active phishing campaign that spoofs Microsoft ADFS single-sign-on pages to harvest credentials and bypass multifactor authentication, enabling account takeover. Approximately 150 organizations—primarily educational institutions—are targeted with personalized fake ADFS pages; attackers use captured credentials and MFA codes to pivot across SSO-connected services, perform reconnaissance, create mail rules to intercept communications, and execute lateral phishing. Recommended mitigations include migrating to modern identity platforms (e.g., Microsoft Entra), adopting phishing-resistant MFA, user training, and enhanced email filtering and behavior monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.