Find notable cyber news and cases, enriched with sources, timelines, and signals.

Custom vishing campaign stealing Okta SSO credentials

Campaign
First reported
Last updated
Happening score
H score 44
2 unique sources, 2 articles

Summary

Hide ▲

A custom vishing campaign is actively stealing Okta SSO credentials through live, adversary-in-the-middle phishing pages, creating immediate risk of account takeover and downstream data theft. Multiple hacking groups are using the service against identity providers such as Google, Microsoft, and Okta, as well as cryptocurrency platforms. The operation relies on spoofed helpdesk calls, real-time MFA relay, and attacker backends such as Telegram to intercept credentials and TOTP codes.

Related Happenings

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord

Campaign
H score37 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...

Microsoft Entra OAuth Client ID spoofing campaign

Campaign
H score58 First: 13.07.2026 16:00 Last: 13.07.2026 16:00 Sources 1

About this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...

Helix vishing and SharePoint data-extortion campaign

Campaign
H score38 First: 09.07.2026 20:08 Last: 09.07.2026 20:08 Sources 1

About this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Timeline

  1. 22.01.2026 23:43 2 articles · 5mo ago

    Okta warns of active vishing credential theft

    Initial Disclosure

    Okta warns that custom phishing kits built for voice-based social engineering are being used in active attacks against employees at identity providers and cryptocurrency platforms, including Okta, Google, and Microsoft, to steal SSO credentials, relay TOTP codes through real-time adversary-in-the-middle pages, and bypass push-based MFA including number matching.

    Show sources