OAuth Device-Code Phishing Compromises 340+ Microsoft 365 Organizations
A device-code phishing campaign has harvested persistent OAuth tokens from Microsoft 365 accounts at over 340 organizations across the U.S., Canada, Australia, New Zealand and Germany since February 2026.