Skip to content
Surge in OAuth Device Code Phishing Targeting Microsoft 365 Accounts

Surge in OAuth Device Code Phishing Targeting Microsoft 365 Accounts

First seen 18 Dec 2025, 16:54 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A rise in phishing campaigns exploiting Microsoft's OAuth device code authorization has been reported, affecting Microsoft 365 accounts. Threat actors, including state-aligned and financially motivated groups, are using social engineering tactics to deceive users into approving malicious applications, leading to account takeovers and data theft. Proofpoint's advisory details these tactics and the ongoing threat landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (6)