logo

Microsoft 365 accounts targeted in wave of OAuth phishing attacks

ID: d1b84b3e-5a49-5d72-9217-dd90398ab6c0

STIX ID: report--d1b84b3e-5a49-5d72-9217-dd90398ab6c0

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-19

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Proofpoint reports a surge in OAuth device code phishing targeting Microsoft 365 accounts where attackers trick users into entering device codes on Microsoft's legitimate device login page to authorize attacker-controlled applications. Campaigns use phishing kits (SquarePhish v1/v2 and Graphish) and lures like document-sharing or token reauthorization; actors include financially motivated groups (TA2723) and a suspected Russia-aligned actor (UNK_AcademicFlare). Proofpoint recommends mitigations such as Microsoft Entra Conditional Access and sign-in origin policies to reduce successful account takeovers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.