Surge in Microsoft 365 Account Takeovers via OAuth Device Code Phishing

Surge in Microsoft 365 Account Takeovers via OAuth Device Code Phishing

First seen 7 Jan 2026, 23:31 UTC CsoonlineItbrief 71% similarity 27.2

Article Content

Browse articles
ThreatCluster

Proofpoint has reported a significant rise in account takeovers of Microsoft 365 users due to the exploitation of Microsoft's OAuth device code authorization flow. Attackers are using a legitimate login process to trick users into entering one-time codes on Microsoft's authentication portal, allowing unauthorized access to corporate accounts. Both financially motivated criminals and state-aligned groups are employing this technique.

ThreatCluster AI

Community

Browse all →