Threat actors are increasingly leveraging OAuth 2.0 device code authorization flows to compromise Microsoft 365 accounts through sophisticated phishing campaigns. Proofpoint researchers have observed both state-aligned and financially motivated groups using social engineering tactics to trick users into granting access to malicious applications, resulting in account takeovers, data exfiltration, and broader SaaS supply chain abuse. Attackers initiate these campaigns with phishing messages containing URLs or QR codes that, when followed, prompt users to authorize access for rogue applications, ultimately handing over OAuth tokens to the adversaries.
Industry analysis highlights that identity-first intrusions, including device code flow phishing and illicit OAuth consent, have driven significant data breaches and business email compromise incidents in 2025. Notable cases include the exploitation of connected apps to exfiltrate data from Salesforce tenants and major financial impacts on organizations such as Marks & Spencer. Security experts recommend enforcing phishing-resistant MFA, governing OAuth consent, and deprecating device code flows where feasible to mitigate these risks. Regulatory changes are also pushing organizations to strengthen identity and SaaS governance in response to these evolving threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In late April 2026, eSentire observed Tycoon 2FA operators repurpose their phishing-as-a-service kit to conduct OAuth device code phishing against Microsoft 365 users. The campaign used Trustifi tracking links and Cloudflare Workers redirects to drive victims to Microsoft's legitimate device login flow, issuing attacker-controlled OAuth tokens instead of stealing passwords directly.
In March 2026, Microsoft and Europol led a takedown targeting Tycoon 2FA infrastructure. Later reporting indicated the operators preserved their codebase and were able to restore operations quickly despite the disruption.
Reporting in 2026 described a major increase in device code phishing attacks. Attackers were using the technique to steal access tokens and bypass standard access controls, making phishing operations more effective.
Proofpoint publicly reported that multiple state-aligned and financially motivated threat clusters were abusing the OAuth 2.0 device authorization grant to compromise Microsoft 365 accounts. The report highlighted tooling such as SquarePhish, SquarePhish2, and Graphish, and recommended restricting or blocking device code flow with Conditional Access and compliant-device requirements.
In October 2025, financially motivated actor TA2723 began using device code phishing in campaigns themed around shared documents and salary-related files. Proofpoint assessed the actor likely used different tooling across campaign waves to scale the attacks.
By September 2025, Proofpoint observed unusually widespread phishing campaigns abusing Microsoft's OAuth device code flow across multiple threat clusters. The campaigns targeted Microsoft 365 users and enabled account takeover, data theft, lateral movement, and persistence while bypassing MFA through legitimate Microsoft verification pages.
By September 2025, the Russia-aligned cluster UNK_AcademicFlare was conducting device code phishing campaigns against targets in government, think tanks, higher education, and transportation in the U.S. and Europe. The group used compromised government and military email accounts plus Cloudflare Worker links spoofing OneDrive to lure victims into authorizing attacker access.
Proofpoint tracks state-aligned use of OAuth 2.0 device authorization grant phishing against Microsoft 365 accounts beginning in January 2025. The activity included Russia-aligned operators using the legitimate Microsoft device login flow to obtain access tokens and take over accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceesentire.com
Open sourceproofpoint.com
Open sourcehelpnetsecurity.com
Open sourceblog.alphahunt.io
Open sourceproofpoint.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.