{"id":214522,"date":"2026-02-17T10:05:00","date_gmt":"2026-02-17T15:05:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/17\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa\/"},"modified":"2026-02-17T11:15:10","modified_gmt":"2026-02-17T16:15:10","slug":"cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/17\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa\/","title":{"rendered":"CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA"},"content":{"rendered":"<p><a href=\"https:\/\/blog.knowbe4.com\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa\">CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA<\/a><\/p>\n<p><a href=\"https:\/\/blog.knowbe4.com\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa\">https:\/\/blog.knowbe4.com\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-17 10:05:00<\/a><\/p>\n<p>Source Domain: <a href=\"blog.knowbe4.com\">blog.knowbe4.com<\/a><\/p>\n<p><span class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"rich_text\"><span class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"rich_text\"><\/span><\/span><br \/>\nCyberheistNews Vol 16 #07\u00a0 | \u00a0 February 17th, 2026<br \/>\n<span class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"rich_text\"><span class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"rich_text\"><\/span><\/span><\/p>\n<p><span style=\"font-size: 24px; line-height: 30px; color: #ef4523;\">Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA<\/span><\/p>\n<p>KnowBe4 Threat Labs has detected a sophisticated phishing campaign targeting North American businesses and professionals. This attack compromises Microsoft 365 accounts (Outlook, Teams, OneDrive) by abusing the OAuth 2.0 Device Authorization Grant flow, bypassing strong passwords and Multi-Factor Authentication (MFA).<\/p>\n<p>The victim is directed to a legitimate Microsoft domain to enter an attack supplied device code. This action authenticates the victim and issues a valid OAuth access token to the attacker&#8217;s application. The real-time theft of these tokens grants the attacker persistent access to the victim&#8217;s Microsoft 365 accounts and corporate data.<\/p>\n<p>Key Takeaways: Campaign at a Glance<\/p>\n<ul style=\"padding-left: 40px; line-height: 1.15;\">\n<li>Novel Attack Mechanism: This campaign bypasses traditional security by not stealing credentials. Instead, it tricks the user into authenticating on the legitimate Microsoft domain, and then polls the token endpoint to capture the OAuth Access and Refresh tokens.<\/li>\n<li>Multi-Factor Authentication (MFA) Bypass: The attack is highly effective as the token theft occurs after the user successfully completes their legitimate MFA challenge.<\/li>\n<li>Targeting: The campaign is active and ongoing (first observed December 2025), is highly concentrated in North America (with 44%+ of victims in the U.S.), and is notably targeting the tech, manufacturing and financial services sectors.<\/li>\n<li>Major Impact: The stolen tokens grant attackers extensive, persistent access to the Microsoft 365 environment, including full read\/write\/send capabilities for Email, Calendar and Files (OneDrive\/SharePoint), and administrative functions.<\/li>\n<li>Immediate Mitigation: Key defenses include urgently auditing recently consented OAuth applications, searching email logs for specific sender and subject patterns, and for IT\/Admin teams, considering the disabling of the device code flow via Conditional Access&#8230;<\/strong><\/p>\n<p><a href=\"https:\/\/blog.knowbe4.com\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA https:\/\/blog.knowbe4.com\/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa Publish Date:&#8230;<\/p>\n","protected":false},"author":1,"featured_media":214523,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blog.knowbe4.com\/hubfs\/CHNNewsletter_Thumbnail.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[25],"class_list":["post-214522","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-phishing"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/214522"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=214522"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/214522\/revisions"}],"predecessor-version":[{"id":214524,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/214522\/revisions\/214524"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/214523"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=214522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=214522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=214522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}