Story perspectives
Microsoft Flags 35K-Victim Phishing Campaign Bypassing MFA
5/6/2026
1 of 1
Story summary
- Microsoft disclosed a phishing campaign that targeted over 35,000 users in 26 countries from April 14-16, 2026.
- Ninety-two percent of victims were in the United States, healthcare, finance and technology.
- Attackers sent emails with PDF attachments that redirected victims to a CAPTCHA and a counterfeit Microsoft sign-in page.
- An adversary-in-the-middle captured authentication tokens in real time, bypassing multi-factor authentication.
- Microsoft urged organizations to enable Auto-Purge, Safe Links, SmartScreen and passwordless authentication.
