ESentire-observed account compromise surged 389% in 2025
Trend
Summary
Hide ▲
Show ▼
Account compromise surged 389% year over year in 2025, making it the dominant observed attack pattern and increasing credential theft and account takeover risk across business users. Microsoft 365 accounts were a prime target, and much of the activity was enabled by phishing-as-a-service (PhaaS) kits. The trend matters because it shows credential abuse is driving a large share of current malicious activity and sustaining BEC operations across multiple sectors.
Related Happenings
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware Activity
H score27
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Jalisco and OmegaLord Microsoft 365 phishing kits
Malware ActivityAbout this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor Meta
H score36
First: 13.07.2026 16:03
Last: 13.07.2026 16:03
Sources 1
About this happening:
Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking
Threat Actor MetaAbout this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
Campaign
H score37
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
O-UNC-066 / Pink Microsoft Entra passkey vishing campaign
CampaignAbout this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...
Pink new extortion brand within The Com
Threat Actor Meta
H score31
First: 08.07.2026 19:47
Last: 08.07.2026 19:47
Sources 1
About this happening:
Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Pink new extortion brand within The Com
Threat Actor MetaAbout this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...
Microsoft Azure CLI password-spray campaign using ROPC
Campaign
H score24
First: 01.07.2026 08:46
Last: 01.07.2026 08:46
Sources 1
About this happening:
A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Microsoft Azure CLI password-spray campaign using ROPC
CampaignAbout this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...
Timeline
-
15.01.2026 02:00 2 articles · 6mo ago
eSentire reports 389% rise in account compromise
Initial DisclosureeSentire's 2025 Year in Review & 2026 Threat Landscape Outlook Report says account compromise rose 389% year over year in 2025, making up 55% of all attacks observed by the cybersecurity firm and 75% of the malicious activity tracked by its Threat Response Unit. The report says credential theft drove most of the activity, Microsoft 365 accounts were prime targets, and phishing-as-a-service kits such as Tycoon2FA, FlowerStorm and EvilProxy enabled account takeovers and business email compromise across sectors including real estate, finance, retail and construction.
Show sources
- Account Compromise Surged 389% in 2025, Says eSentire — www.infosecurity-magazine.com — 16.01.2026 13:40
- Account Compromise Surged 389% in 2025, Says eSentire — www.infosecurity-magazine.com — 16.01.2026 13:40