Custom vishing campaign stealing Okta SSO credentials
Campaign
Summary
Hide ▲
Show ▼
A custom vishing campaign is actively stealing Okta SSO credentials through live, adversary-in-the-middle phishing pages, creating immediate risk of account takeover and downstream data theft. Multiple hacking groups are using the service against identity providers such as Google, Microsoft, and Okta, as well as cryptocurrency platforms. The operation relies on spoofed helpdesk calls, real-time MFA relay, and attacker backends such as Telegram to intercept credentials and TOTP codes.
Related Happenings
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Timeline
-
22.01.2026 23:43 2 articles · 5mo ago
Okta warns of active vishing credential theft
Initial DisclosureOkta warns that custom phishing kits built for voice-based social engineering are being used in active attacks against employees at identity providers and cryptocurrency platforms, including Okta, Google, and Microsoft, to steal SSO credentials, relay TOTP codes through real-time adversary-in-the-middle pages, and bypass push-based MFA including number matching.
Show sources
- Okta SSO accounts targeted in vishing-based data theft attacks — www.bleepingcomputer.com — 22.01.2026 23:43
- Okta Flags Customised, Reactive Vishing Attacks Which Bypass MFA — www.infosecurity-magazine.com — 26.01.2026 14:12