Device-code phishing service compromised 12,000 Microsoft inboxes
Daily Cyber News: Device-code phishing service compromised 12,000 Microsoft inboxes
More than twelve thousand Microsoft inboxes across over ten thousand organizations were compromised through the EvilTokens phishing service. The platform abused legitimate device-code authentication. Victims were guided through a real Microsoft login, but the process authorized an attacker’s session instead of their own intended device.
Key context: Compromised inboxes can enable payment fraud, executive impersonation, and follow-on attacks against trusted customers and suppliers.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, phishing, Device-code, service, compromised, Microsoft, inboxes.