08/03/2026
The FBI has issued a warning about a new type of phishing attack targeting Microsoft 365 users ๐ฐ
And this one's a little bit differentโฆ
Normally with phishing attacks, the attacker tries to steal your password.
This time, theyโre trying to steal something called an โOAuth tokenโ.
An OAuth token is like a temporary digital pass that proves youโve already logged in successfully.
Itโs what keeps you signed in on certain apps like Outlook, Teams, and OneDrive without needing to re-enter your password every few minutes.
So, If an attacker gets access to that token, they could also access your services as if they were actually you. ๐ฅธ
And the phishing emails themselves are becoming incredibly convincing, thanks to AI...
They can appear as shared documents, meeting invites, or even account notifications. And can often lead to real Microsoft login pages.
So, when someone approves the request, it seems perfectly legitimate.
Thatโs exactly the same trap in which the attacker is effectively getting you to approve access to, on their behalf.
This is a perfect example of exactly why cybersecurity is changing so rapidly right now.
For years, businesses focused heavily on securing passwords and antivirus software. And while those aspects are still important, attackers are increasingly finding successful work-arounds by targeting normal human behavior instead;
A rushed click or an approval without thinking is but a momentary distraction during a busy day; and its often all they need to strike.
Fortunately, there are protections you can put in place behind the scenes, especially around how Microsoft 365 handles authentication requests.
For now, its best to remember that if you receive an unexpected login request, verification prompt, or email asking you to approve access to anything.., ๐๐น๐ผ๐ ๐ฑ๐ผ๐๐ป ๐ฎ๐ป๐ฑ ๐๐ต๐ถ๐ป๐ธ ๐ฏ๐ฒ๐ณ๐ผ๐ฟ๐ฒ ๐ฐ๐น๐ถ๐ฐ๐ธ๐ถ๐ป๐ด ๐ฎ๐ป๐๐๐ต๐ถ๐ป๐ด!
๐ Have you noticed that phishing emails are harder to spot lately?
Tell us your input!
https://api.mspsites.com/sp/cf2684412c3