Microsoft says a phishing campaign targeted 10K+ organizations since September 2021 by hijacking Office 365's authentication process even on accounts using MFA
Campaign that steals email has targeted at least 10,000 organizations since October. — On Tuesday, Microsoft detailed …
Context & Ripple Effects
Microsoft's disclosure sits alongside its phishing-as-a-service operation finding from the same period, showing that scalable phishing tooling was already being sold with extensive templates. The important distinction here is that the campaign targeted the authentication path rather than simply trying to collect passwords.
Later Microsoft reporting on OAuth-app abuse for phishing and spam and its removal of fraudulent partner accounts used for malicious OAuth apps extends the arc: email theft campaigns increasingly exploit trusted identity and application mechanisms around Microsoft cloud accounts.
First-order effects
- Organizations targeted by the campaign face email compromise even where affected accounts use MFA, because the attack hijacks the Office 365 authentication process rather than relying on a password alone.
- Microsoft and Office 365 administrators must treat the authentication flow itself as an attack surface, not MFA enrollment as a complete control against phishing-driven email theft.
Second-order effects
- Microsoft's cloud customers must scrutinize consented applications and authentication activity alongside conventional phishing defenses, a pressure reinforced by the later OAuth-app misuse reports.
- Phishing operators gain a route to higher-value email access by targeting authenticated sessions and connected apps, raising the stakes for Microsoft controls over identity and partner ecosystems.
Third-order effects
- If authentication-hijacking and malicious-app campaigns continue to recur, enterprise email security will shift from credential protection toward governance of sessions, application consent, and trusted-account pathways.
- Microsoft's repeated disclosures point to a structural contest over cloud identity: platform safeguards and customer identity practices must adapt as attackers target the mechanisms designed to make login more secure.
The trend: Cloud phishing is evolving from password theft toward abuse of authenticated sessions and identity-linked applications that can sidestep MFA's narrow protection against credential reuse.