Threats & Adversaries · Phishing / BEC
MFA is not the control point here. A user who accepts an OAuth consent prompt can hand over a long-lived refresh token, so the attacker keeps tenant-scoped access after the login looks normal and the alerting stays quiet.
EvilTokens reportedly went live in February 2026 and, within five weeks, compromised more than 340 Microsoft 365 organizations across five countries. The access reaches mailbox, drive, calendar, and contacts data, and it can survive beyond a single session because the token is refreshable.
The risk is persistent tenant access that standard sign-in telemetry can miss. Once consent is granted, the usual password-and-MFA playbook does not describe the real entry point anymore.
1 source · May 19
The Hacker News
The New Phishing Click: How OAuth Consent Bypasses MFA
OAuth consent is the phishing vector MFA misses—long-lived tokens and cross-app access bypass trusted identity controls.
originalPart of the PlainSec briefing for 2026-05-19
Every edition of this story: OAuth Consent Turns MFA-Protected Tenants Into Token Farms