Microsoft Entra device code phishing and vishing campaign
Campaign
Summary
Hide ▲
Show ▼
A device code phishing campaign is targeting Microsoft 365 identities through the OAuth 2.0 device authorization flow, letting attackers steal valid access tokens after victims enter codes on Microsoft’s trusted verification page. A new Proofpoint advisory says multiple threat clusters, including TA2723 and UNK_AcademicFlare, used this technique to gain unauthorized access, enable account takeover and data theft, and scale abuse with QR codes, embedded buttons, hyperlinks, fake shared documents, and localized sites. Proofpoint said the activity was increasingly observed by September 2025, with one campaign on December 8 using a fake shared document titled “Salary Bonus + Employer Benefit Reports 25.” The report also tied the expansion to tools such as SquarePhish2 and Graphish, and said organizations should strengthen OAuth controls and train users not to enter device codes from untrusted sources.
Related Happenings
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
Campaign
H score37
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
Microsoft 365 device-code phishing campaign using Jalisco and OmegaLord
CampaignAbout this happening: The Jalisco and OmegaLord campaign is targeting Microsoft 365 accounts with MFA-bypass phishing, putting credentials, sessions, and downstream data at risk. Jalisc...
ShinyHunters-linked Salesforce intrusion campaign
Campaign
H score45
First: 14.07.2026 09:19
Last: 14.07.2026 09:19
Sources 1
About this happening:
A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
ShinyHunters-linked Salesforce intrusion campaign
CampaignAbout this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...
Microsoft Entra OAuth Client ID spoofing campaign
Campaign
H score58
First: 13.07.2026 16:00
Last: 13.07.2026 16:00
Sources 1
About this happening:
A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Microsoft Entra OAuth Client ID spoofing campaign
CampaignAbout this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...
Timeline
-
19.02.2026 14:30 5 articles · 4mo ago
Microsoft Entra device code phishing and vishing campaign
Initial DisclosureThreat actors are targeting technology, manufacturing, and financial organizations with device code phishing and voice phishing (vishing) that abuse the OAuth 2.0 Device Authorization flow to obtain valid authentication tokens for Microsoft Entra accounts. The workflow uses legitimate Microsoft OAuth client IDs and the microsoft.com/devicelogin page to persuade employees to enter a generated user_code, which can then be exchanged for access tokens that reach Microsoft 365 and other SSO-linked SaaS applications without another MFA prompt. KnowBe4 Threat Labs also identified a related campaign using phishing emails and websites, with fake payment configuration prompts, document-sharing alerts, and bogus voicemail notifications, first spotted in December 2025; Microsoft Threat Intelligence Center had previously warned in February 2025 about device code phishing against Microsoft 365 accounts.
Show sources
- Hackers target Microsoft Entra accounts in device code vishing attacks — www.bleepingcomputer.com — 19.02.2026 14:30
- Hackers target Microsoft Entra accounts in device code vishing attacks — www.bleepingcomputer.com — 19.02.2026 14:30
- Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication — thehackernews.com — 03.03.2026 13:10
- Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse — thehackernews.com — 25.03.2026 13:34
- OAuth Device Code Phishing Campaigns Surge Targets Microsoft 365 — www.infosecurity-magazine.com — 18.12.2025 18:00