Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Teams OAuth phishing campaign targeting 120 organizations

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts across 120 organizations. The operation used fake Teams and Planner notifications to push victims into approving access through a legitimate authorization flow. Successful logins gave attackers tokens and access to Outlook, SharePoint, and OneDrive. The same access could be reused for Business Email Compromise (BEC) and inbox data exfiltration.

Related Happenings

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
H score34 First: 24.07.2026 20:50 Last: 24.07.2026 20:50 Sources 1

About this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...

EvilTokens Microsoft 365 consent phishing campaign

Campaign
H score39 First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...

Timeline

  1. 29.07.2026 03:00 2 articles · 1d ago

    Teams-themed phishing campaign abused Microsoft authentication infrastructure

    Initial Disclosure

    Check Point warned that attackers were running a Teams-themed phishing campaign that abused Microsoft’s legitimate authentication infrastructure instead of fake login pages, using emails that impersonated Microsoft Teams and Microsoft Planner notifications. Victims who approved the OAuth consent prompt could hand attackers access to corporate Outlook, SharePoint, OneDrive, and Microsoft 365 accounts, and the campaign targeted users at 120 organizations across manufacturing, legal, and healthcare.

    Show sources