See every side of every news story
Published loading...Updated

Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts

  • Suspected Russian actors launched targeted OAuth phishing campaigns against Microsoft 365 users in March 2025.
  • These attacks abuse legitimate Microsoft authentication workflows, evolving from similar February 2025 phishing observed by Volexity.
  • Attackers impersonate European officials and use messaging apps like Signal or WhatsApp to initiate contact with targets.
  • The scheme tricks victims into sharing Microsoft authorization codes that grant attackers account access, according to Volexity researchers.
  • Gaining access allows attackers to join devices to Entra ID and download emails and other sensitive data.
Insights by Ground AI
Does this summary seem wrong?

15 Articles

All
Left
1
Center
3
Right
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 75% of the sources are Center
75% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Malware Analysis, News and Indicators broke the news in on Tuesday, April 22, 2025.
Sources are mostly out of (0)

You have read out of your 5 free daily articles.

Join us as a member to unlock exclusive access to diverse content.