Surge in Microsoft 365 Account Takeovers via OAuth Device Code Phishing
First seen 7 Jan 2026, 23:31 UTC
•
•71% similarity
•27.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Proofpoint has reported a significant rise in account takeovers of Microsoft 365 users due to the exploitation of Microsoft's OAuth device code authorization flow. Attackers are using a legitimate login process to trick users into entering one-time codes on Microsoft's authentication portal, allowing unauthorized access to corporate accounts. Both financially motivated criminals and state-aligned groups are employing this technique.
ThreatCluster AI