Just in:
Cisco flaw hit before public warning // OTC & Partners Opens 2026 with Strong Cross-Border Mandates and Strategic Expansion // Golden Bridge Real Estate Unveils Special Summer Offers Across Mashriq Elite Developments on July 1, 2026 // Altcoins resist as Bitcoin absorbs June shock // Dubai Holding eyes European data centre foothold // Vinmec Launches Vietnam’s First Integrated High-Tech Robotic Surgery Network, Establishing the Country’s First Multi-Connected Robotic Surgery Ecosystem // Lower oil risks lift UAE wealth outlook // Tether widens gold strategy with XAUT loans // Where Minds Meet to Launch Space Economy Association Off the Ground // Cloud bucket flaw exposes silent data theft risk // Ras Tanura crash kills Aramco personnel // Canvas breach sharpens UK campus cyber warning // Christopher Aleo Strengthens His Gulf Presence with a New Tourism Investment in Oman // Bracell Welcomes Fernando Branco’s Appointment to Lead ABAF and Reinforces Commitment to Sustainable Forestry Development in Bahia // PlayStation sales hit May low // Anthropic reopens Mythos 5 for cyber defenders // Construction Management Awards 2026 – Now open for nomination Introduction of the Inaugural “Excellent Construction Safety Culture Award” Guides the Construction Industry Toward a New Milestone in Safety // Afogreen Build Highlights Growing Adoption of Building Performance Modelling in Australia’s Sustainability-Driven Construction Sector // UAE anchors AI supply push in Washington // BOCHK expo spotlights Hong Kong wealth shift //

Microsoft login ruse hits firms worldwide

Hundreds of organisations using Microsoft 365 are facing a fast-growing phishing threat that sidesteps conventional multi-factor authentication controls by abusing a legitimate Microsoft sign-in process rather than breaking it. Security researchers tracking the activity say more than 340 organisations across the United States, Canada, Australia, New Zealand and Germany have been affected, with attacks accelerating through March after the first known cases were detected on February 19.

The campaign centres on what security specialists call device code phishing, a technique that turns a genuine Microsoft login feature into a trap. The feature was designed for devices such as smart televisions, printers and terminals that cannot easily complete a normal browser sign-in. Attackers generate a valid device code, lure a target to a convincing phishing page, and persuade that user to enter the code on Microsoft’s legitimate device login page. Once the target approves the request, the attackers receive valid access and refresh tokens, giving them account access without having to steal a password in the traditional way.

That distinction matters because it means the attackers are not exploiting a software flaw in Microsoft 365 itself. Microsoft said in earlier guidance on device code phishing that these attacks do not reflect a vulnerability in its code base, but rather the misuse of an industry-standard authentication flow. Even so, the effect for victims can be severe. Access tokens allow immediate entry into cloud resources, while refresh tokens can extend access for weeks, enabling email theft, internal reconnaissance and, in some cases, wider business email compromise activity.

ADVERTISEMENT

Researchers at Huntress, which disclosed the latest campaign, said the activity spread sharply from a small number of incidents in late February to a much broader wave by March 2, cutting across sectors from law firms and construction businesses to healthcare, finance, manufacturing, nonprofits and public-sector bodies. CyberScoop reported Huntress believed the victims identified so far could represent only a fraction of the true total, suggesting the global footprint may be larger than the confirmed list.

Part of what has unsettled defenders is the way the infrastructure blends in with normal cloud traffic. Huntress said the campaign made heavy use of Railway, a platform-as-a-service provider better known for helping developers deploy applications quickly. Because Railway’s internet addresses belong to a legitimate cloud service, sign-ins originating from those systems may not immediately appear suspicious in automated risk scoring. Huntress described the platform as a “clean” token-harvesting engine from a defender’s perspective, giving attackers a way to stand up and rotate phishing infrastructure with unusual speed.

Railway told CyberScoop it was first contacted on March 6 about phishing traffic linked to a specific IP address and three domains, and said the associated accounts were banned and the domains blocked. A company engineer added that the firm’s anti-abuse systems are designed to detect repeated patterns such as shared payment details, code sources and overlapping infrastructure, but that a campaign avoiding those signals can travel further before it is stopped. That response points to a wider problem across cloud services: low-friction development platforms can become equally low-friction tools for cybercrime when identity checks and abuse controls lag behind attacker adaptation.

Huntress later tied the Railway-linked activity to a phishing-as-a-service operation known as EvilTokens, which it said was advertised publicly in mid-February on Telegram channels. According to Huntress, the service offered customers tools branded as a “B2B Sender”, an “Office 365 Capture Link” and an “SMTP Sender”, alongside features aimed at tailoring lures and evading email filtering. That commercialisation is significant. It suggests the barrier to mounting advanced Microsoft 365 phishing operations is falling, with criminal operators packaging infrastructure, templates and support into rentable services.

The campaign also shows how identity attacks are evolving beyond the older narrative that MFA alone is enough. Microsoft has repeatedly warned over the past year that device code phishing and adversary-in-the-middle techniques can undermine authentication flows that are not phishing-resistant. In its guidance this month on large-scale phishing operations and earlier research into the Storm-2372 campaign, Microsoft urged organisations to move towards phishing-resistant authentication methods such as FIDO2 security keys, passkeys and Windows Hello for Business, while blocking device code flow where it is not required.


Also published on Medium.

ADVERTISEMENT


Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com
Just in:
Where Minds Meet to Launch Space Economy Association Off the Ground // Golden Bridge Real Estate Unveils Special Summer Offers Across Mashriq Elite Developments on July 1, 2026 // Bracell Welcomes Fernando Branco’s Appointment to Lead ABAF and Reinforces Commitment to Sustainable Forestry Development in Bahia // Christopher Aleo Strengthens His Gulf Presence with a New Tourism Investment in Oman // Gulf bases drawn into US-Iran strikes // Ras Tanura crash kills Aramco personnel // Tether widens gold strategy with XAUT loans // UAE false missile alert traced to glitch // TCL Supports “2026 Olympic Day cum Aichi-Nagoya Asian Games Fun Run”, Celebrating the Olympic Spirit with Athletes and the Public, and Offering Lucky Draw Prizes Worth Approximately HK$180,000 // Dubai Holding eyes European data centre foothold // TAEF sukuk deepens Dubai debt market // 7 Law Firms Making a Difference in Charleston, SC // Why a Growing Number of German-Speaking Founders Are Choosing Dubai // Canvas breach sharpens UK campus cyber warning // PlayStation sales hit May low // Construction Management Awards 2026 – Now open for nomination Introduction of the Inaugural “Excellent Construction Safety Culture Award” Guides the Construction Industry Toward a New Milestone in Safety // Vinmec Launches Vietnam’s First Integrated High-Tech Robotic Surgery Network, Establishing the Country’s First Multi-Connected Robotic Surgery Ecosystem // Cloud bucket flaw exposes silent data theft risk // UAE anchors AI supply push in Washington // Lower oil risks lift UAE wealth outlook //