logo

Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries

ID: 43f113ec-c9fd-51d7-9b06-c78f40ce8cbb

STIX ID: report--43f113ec-c9fd-51d7-9b06-c78f40ce8cbb

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed a multi-stage credential-harvesting phishing campaign (Apr 14–16, 2026) that targeted >35,000 users across ~13,000 organizations using polished code-of-conduct lures, PDFs with links, CAPTCHA-gated intermediary pages and AiTM phishing to capture credentials and tokens (bypassing MFA); the report also outlines Q1 2026 phishing trends including a surge in QR-code phishing, widespread use of PhaaS platforms (Tycoon 2FA, Kratos, EvilTokens) and abuse of Amazon SES to evade email authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.