Story perspectives
Phishing Surge: Microsoft OAuth Exploited by Attackers
12/20/2025
1 of 1
Story summary
- Proofpoint reports phishing attacks exploiting Microsoft's OAuth device code flow.
- Financially motivated and state-aligned groups use social engineering to access Microsoft 365 accounts.
- Attackers deploy QR codes and hyperlinked text disguising requests as document sharing or security verifications.
- One group linked to Russia targeted sectors in the United States and Europe.
- Proofpoint advises stronger OAuth controls and user education to avoid untrusted codes, predicting continued growth.
