Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Entra device code phishing and vishing campaign

Campaign
First reported
Last updated
Happening score
H score 40
3 unique sources, 4 articles

Summary

Hide ▲

A device code phishing campaign is targeting Microsoft 365 identities through the OAuth 2.0 device authorization flow, letting attackers steal valid access tokens after victims enter codes on Microsoft’s trusted verification page. A new Proofpoint advisory says multiple threat clusters, including TA2723 and UNK_AcademicFlare, used this technique to gain unauthorized access, enable account takeover and data theft, and scale abuse with QR codes, embedded buttons, hyperlinks, fake shared documents, and localized sites. Proofpoint said the activity was increasingly observed by September 2025, with one campaign on December 8 using a fake shared document titled “Salary Bonus + Employer Benefit Reports 25.” The report also tied the expansion to tools such as SquarePhish2 and Graphish, and said organizations should strengthen OAuth controls and train users not to enter device codes from untrusted sources.

Related Happenings

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord

Campaign
H score37 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...

ShinyHunters-linked Salesforce intrusion campaign

Campaign
H score45 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...

Microsoft Entra OAuth Client ID spoofing campaign

Campaign
H score58 First: 13.07.2026 16:00 Last: 13.07.2026 16:00 Sources 1

About this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...

Timeline

  1. 19.02.2026 14:30 5 articles · 4mo ago

    Microsoft Entra device code phishing and vishing campaign

    Initial Disclosure

    Threat actors are targeting technology, manufacturing, and financial organizations with device code phishing and voice phishing (vishing) that abuse the OAuth 2.0 Device Authorization flow to obtain valid authentication tokens for Microsoft Entra accounts. The workflow uses legitimate Microsoft OAuth client IDs and the microsoft.com/devicelogin page to persuade employees to enter a generated user_code, which can then be exchanged for access tokens that reach Microsoft 365 and other SSO-linked SaaS applications without another MFA prompt. KnowBe4 Threat Labs also identified a related campaign using phishing emails and websites, with fake payment configuration prompts, document-sharing alerts, and bogus voicemail notifications, first spotted in December 2025; Microsoft Threat Intelligence Center had previously warned in February 2025 about device code phishing against Microsoft 365 accounts.

    Show sources