Identity · 7h ago

N0va Turns SSO Phishing into Durable Cloud Access

The N0va phishkit is targeting organizations in North America and Europe and using trusted-looking sign-in pages to steal OAuth access and refresh tokens, The Hacker News reports. The campaign has been seen against government, technology, consulting, healthcare, and other sectors.

The trick is to run the victim through a legitimate authentication flow, then capture tokens the attacker can reuse later. Those tokens act like standing keys: with them, an attacker can reopen the account, reach email and business apps, and keep access even after a password change if the sessions and grants are still live.

That makes the blast radius an identity problem, not just a bad click. Any shop that relies on SSO for cloud services inherits the same risk: token theft can preserve footholds in trusted accounts and quietly extend dwell time across the cloud estate.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-16

Editions

Related stories