Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens for Persistent Access

A phishing campaign has been identified exploiting Microsoft’s OAuth 2.0 Device Authorization Grant flow to gain unauthorized and persistent access to Microsoft 365 accounts. This campaign, active since December 2025, primarily targets professionals and…

A phishing campaign has been identified exploiting Microsoft’s OAuth 2.0 Device Authorization Grant flow to gain unauthorized and persistent access to Microsoft 365 accounts. This campaign, active since December 2025, primarily targets professionals and enterprises in North America, with 44% of victims located in the United States. Impacted sectors include technology, manufacturing, and financial services.

The attack circumvents traditional credential theft and multi-factor authentication (MFA) by manipulating the authentication flow. Victims unknowingly assist attackers in obtaining valid OAuth access and refresh tokens, granting full access to corporate Microsoft 365 environments.

The attack involves registering a malicious application on Microsoft’s OAuth platform to generate a unique device code. This code is embedded in a phishing email sent to targeted individuals. The email employs social engineering tactics, such as fake payment notifications, to prompt recipients to click on an embedded link.

Victims who follow the link are directed to an attacker-controlled landing page that mimics legitimacy. They are instructed to visit Microsoft’s official portal at microsoft.com/devicelogin and enter the provided device code as part of a “secure authentication” process. Upon entering the code and completing the authentication process, including MFA, Microsoft issues OAuth tokens that provide the attacker with full account access.

Impacted sectors include technology, manufacturing, and financial services.
Danielle Frost · Thehackingpost

These tokens enable the attacker to perform actions such as reading and sending emails, accessing OneDrive and SharePoint files, scheduling meetings, and executing administrative tasks without re-entering credentials or triggering MFA challenges.

The persistence of this campaign is particularly damaging, as refresh tokens allow attackers to generate new access tokens continuously. This keeps a backdoor open to the victim’s Microsoft 365 account for as long as the tokens remain valid, posing risks to corporate data and sensitive communications even after password resets or MFA reconfigurations.

Organizations are advised to audit all recently consented OAuth applications in their Microsoft 365 environment and identify suspicious apps not explicitly approved by users. Additionally, IT teams should monitor email gateways and logs for recurring sender patterns or subject lines indicating phishing attempts.

Advertisement

Security measures include disabling device code flow for nonessential use through Conditional Access policies and educating employees about OAuth-based phishing. As attackers increasingly exploit trusted authentication flows, defense strategies must evolve beyond password and MFA protections. Continuous monitoring and strict application consent policies are essential to prevent OAuth token abuse within enterprise ecosystems.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories