08/01/2026
The FBI has issued a warning about a new type of phishing attack targeting Microsoft 365 users 😰
And this one is a little different…
Normally with phishing, the attacker tries to steal your password.
This time, they’re trying to steal something called an “OAuth token”.
A what?!
An OAuth token is like a temporary digital pass that proves you’ve already logged in successfully.
It’s what keeps you signed into apps like Outlook, Teams, and OneDrive without needing to enter your password every few minutes.
If an attacker steals that pass, they can potentially access those services as if they were you 🥸
The phishing emails themselves are becoming incredibly convincing, thanks to AI.
They can look like document shares, meeting invites, or account notifications. And they often lead to real Microsoft login pages.
So, when someone approves the request, it feels legitimate.
That’s the trap 🪤 The attacker is effectively getting you to approve access on their behalf.
This is why cybersecurity is changing so much right now.
For years, businesses focused heavily on passwords and antivirus software, and those are still important.
But attackers are increasingly finding ways to work around them by targeting normal human behavior instead.
A rushed click, an approval without thinking, a moment of distraction during a busy day. That’s often all they need.
Fortunately, there are protections you can put in place behind the scenes, especially around how Microsoft 365 handles authentication requests.
And remember, if you receive an unexpected login request, verification prompt, or email asking you to approve access to something, slow down and think before clicking anything 🔎
Even if it looks genuine.
👉 Have you noticed that phishing emails are harder to spot lately?