Find notable cyber news and cases, enriched with sources, timelines, and signals.

ESentire-observed account compromise surged 389% in 2025

Trend
First reported
Last updated
Happening score
H score 52
1 unique sources, 1 articles

Summary

Hide ▲

Account compromise surged 389% year over year in 2025, making it the dominant observed attack pattern and increasing credential theft and account takeover risk across business users. Microsoft 365 accounts were a prime target, and much of the activity was enabled by phishing-as-a-service (PhaaS) kits. The trend matters because it shows credential abuse is driving a large share of current malicious activity and sustaining BEC operations across multiple sectors.

Related Happenings

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Pink new extortion brand within The Com

Threat Actor Meta
H score31 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: Pink is a The Com-linked extortion brand associated with O-UNC-066 that is now being used in a voice-based phishing campaign against Microsoft 365 users. The a...

Microsoft Azure CLI password-spray campaign using ROPC

Campaign
H score24 First: 01.07.2026 08:46 Last: 01.07.2026 08:46 Sources 1

About this happening: A massive automated password-spray campaign against Microsoft Azure CLI compromised at least 78 accounts across 64 organizations, expanding access risk across clou...

Timeline

  1. 15.01.2026 02:00 2 articles · 6mo ago

    eSentire reports 389% rise in account compromise

    Initial Disclosure

    eSentire's 2025 Year in Review & 2026 Threat Landscape Outlook Report says account compromise rose 389% year over year in 2025, making up 55% of all attacks observed by the cybersecurity firm and 75% of the malicious activity tracked by its Threat Response Unit. The report says credential theft drove most of the activity, Microsoft 365 accounts were prime targets, and phishing-as-a-service kits such as Tycoon2FA, FlowerStorm and EvilProxy enabled account takeovers and business email compromise across sectors including real estate, finance, retail and construction.

    Show sources