Threats · 178 days ago

OAuth Device-Code Phishing Compromises 340+ Microsoft 365 Organizations

A device-code phishing campaign has harvested persistent OAuth tokens from Microsoft 365 accounts at over 340 organizations across the U.S., Canada, Australia, New Zealand and Germany since February 2026.

Timeline

Sources

5 sources covering this story

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-04-01

Related stories