Identity · 7h ago
The N0va phishkit is targeting organizations in North America and Europe and using trusted-looking sign-in pages to steal OAuth access and refresh tokens, The Hacker News reports. The campaign has been seen against government, technology, consulting, healthcare, and other sectors.
The trick is to run the victim through a legitimate authentication flow, then capture tokens the attacker can reuse later. Those tokens act like standing keys: with them, an attacker can reopen the account, reach email and business apps, and keep access even after a password change if the sessions and grants are still live.
That makes the blast radius an identity problem, not just a bad click. Any shop that relies on SSO for cloud services inherits the same risk: token theft can preserve footholds in trusted accounts and quietly extend dwell time across the cloud estate.
1 source covering this story
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va phishing abuses legitimate authentication flows to capture access and refresh tokens and establish SSO access to corporate resources.
Part of the PlainSec briefing for 2026-09-16