OAuth Device-Code Phishing Compromises 340+ Microsoft 365 Organizations

A device-code phishing campaign has harvested persistent OAuth tokens from Microsoft 365 accounts at over 340 organizations across the U.S., Canada, Australia, New Zealand and Germany since February 2026.

Part of the PlainSec briefing for 2026-04-01

Sources