Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New AiTM Attack Campaign That Bypasses MFA Targeting Microsoft 365 and Okta Users

A recent phishing campaign has been identified that effectively bypasses multi-factor authentication (MFA) for Microsoft 365 and Okta users, posing a significant risk to organizations using these platforms for identity management.

A recent phishing campaign has been identified that effectively bypasses multi-factor authentication (MFA) for Microsoft 365 and Okta users, posing a significant risk to organizations using these platforms for identity management.

Discovered in early December 2025, the campaign reveals advanced understanding of authentication processes. It targets organizations across various sectors through phishing emails disguised as HR and benefits notifications.

The phishing campaign utilizes sophisticated techniques to intercept legitimate single sign-on (SSO) workflows, allowing attackers to capture user credentials and session tokens before MFA can prevent unauthorized access. Attackers have registered several lookalike domains such as sso.okta-secure.io, sso.okta-cloud.com, and sso.okta-access.com to mimic authentic authentication pages.

The phishing emails originate from compromised Salesforce Marketing Cloud accounts and use compensation-related lures. They include shortened links that redirect recipients to initial phishing domains hosted on Cloudflare infrastructure. The attack remains active, with numerous organizations reporting incidents.

Discovered in early December 2025, the campaign reveals advanced understanding of authentication processes.
Katherine Doyle · Thehackingpost

The attack involves a two-stage phishing process leveraging JavaScript-based credential harvesting. Initially, attackers proxy legitimate Okta pages, injecting malicious scripts that capture usernames and monitor session cookies. These scripts continually track critical cookies such as idx, JSESSIONID, proximity_, DT, and sid, essential for maintaining authenticated sessions.

JavaScript-Based Credential Capture Mechanism

The phishing technique exploits the window.fetch method to redirect legitimate requests from Okta to the attacker’s phishing domain. It captures user credentials via DOM event listeners, storing them in localStorage, sessionStorage, and cookies, ensuring persistence across page navigations or storage clearances.

For users employing Okta with Microsoft 365, the attack monitors responses from Microsoft's authentication endpoint, modifying the FederationRedirectUrl field to redirect users to a second-stage phishing page. This seamless redirection proxies all traffic to the legitimate Okta tenant, facilitating unauthorized access with captured session cookies.

Advertisement

Organizations should scrutinize Okta logs for auth_via_mfa events with mismatched Cloudflare IP origins and implement phishing-resistant MFA methods like FIDO2 security keys to counter such attacks.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories