AI-driven phishing and public-facing application exploitation rise across Microsoft telemetry incidents
Trend
Summary
Hide ▲
Show ▼
Microsoft Digital Defense Report 2026 shows AI is speeding attacks up and shifting initial access patterns across observed incidents, increasing defender pressure. Phishing rose from 7% of incidents in 2025 to 23% in 2026, while public-facing application exploitation also climbed. The same period saw post-compromise activity such as credential discovery, data exfiltration, and lateral movement compress from days to minutes.
Related Happenings
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Latest development: 05.08.2026 14:43
Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.
EvilTokens Microsoft 365 consent phishing campaign
Campaign
H score39
First: 19.05.2026 14:30
Last: 19.05.2026 14:30
Sources 1
About this happening:
The EvilTokens campaign is a Microsoft 365 device-code phishing PhaaS that began in February 2026 and abused microsoft.com/devicelogin to steal authentication...
EvilTokens Microsoft 365 consent phishing campaign
CampaignAbout this happening: The EvilTokens campaign is a Microsoft 365 device-code phishing PhaaS that began in February 2026 and abused microsoft.com/devicelogin to steal authentication...
Latest development: 22.09.2026 18:00
Microsoft coordinated with Health-ISAC, law enforcement, and SpyCloud to seize active EvilTokens infrastructure, disrupting the phishing service after it compromised more than 12,000 Microsoft accounts across over 10,000 organizations. The Metropolitan Police Service also arrested two suspected EvilTokens administrators in the U.K. after executing warrants at addresses in Canary Wharf and Nine Elms.
Code of conduct-themed Microsoft AiTM phishing campaign
Campaign
H score53
First: 05.05.2026 09:35
Last: 05.05.2026 09:35
Sources 1
About this happening:
A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...
Code of conduct-themed Microsoft AiTM phishing campaign
CampaignAbout this happening: A large-scale phishing campaign used code of conduct-themed lures and legitimate email services to push victims to attacker-controlled domains and steal authentication t...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
02.10.2026 17:15 2 articles · 2h ago
AI-driven phishing and public-facing application exploitation rise across Microsoft telemetry incidents
Initial DisclosureBy 2026, observed attacks had shifted toward AI-assisted entry and faster post-compromise movement, with phishing and public-facing application exploitation both rising sharply. The earliest attack stages changed the most, reducing the time defenders have to detect and contain compromise.
Show sources
- Microsoft: AI Cuts Post-Compromise Attack Time to Minutes — www.infosecurity-magazine.com — 02.10.2026 17:15
- Microsoft: AI Cuts Post-Compromise Attack Time to Minutes — www.infosecurity-magazine.com — 02.10.2026 17:15