01/08/2026
Cyber threats are evolving continuously, with new attacks being planned and executed on an ongoing basis. This particular attack steals your session token allowing the takeover of your Microsoft 365 account via a phishing attack leaving users unaware that they have just handed over access. We see this most often done where a phishing email is received sharing a file, the user is prompted to login with their email credentials, then enter the MFA code. The attacker then takes that secure token and uses it from their side to gain access to the account. Do not assume that these attacks are only being directed towards large companies, small businesses are experiencing the same vulnerabilities. This article from IT Brief Australia, explains what is happening well, it’s worth reading.
There are steps that can be taken to help lessen your exposure, using conditional access and Intune, limiting access to email and company data on personal devices, as well as many other security policies. These measures do come at a cost, but they are becoming very necessary.
Proofpoint flags a sharp rise in Microsoft 365 account takeovers via device code phishing, hitting firms from finance to government.