Surge in OAuth Device Code Phishing Targeting Microsoft 365 Accounts

Surge in OAuth Device Code Phishing Targeting Microsoft 365 Accounts

First seen 18 Dec 2025, 16:54 UTC Infosecurity-MagazineProofpointCybersecuritydiveBleepingcomputer 26.3

Article Content

Browse articles
ThreatCluster

A rise in phishing campaigns exploiting Microsoft's OAuth device code authorization has been reported, affecting Microsoft 365 accounts. Threat actors, including state-aligned and financially motivated groups, are using social engineering tactics to deceive users into approving malicious applications, leading to account takeovers and data theft. Proofpoint's advisory details these tactics and the ongoing threat landscape.