The FBI is warning about a new phishing attack targeting Microsoft 365 users 😰
But this one’s a little different…
With phishing, attackers usually try to steal your password.
This time, they’re going for something called an “OAuth token”.
What is that?
Think of an OAuth token as a temporary digital ticket that proves you've successfully signed in, so you don't need to enter your credentials again for every request.
That’s how you stay signed into apps like Outlook, Teams, and OneDrive without having to sign in again every few minutes.
If an attacker can get your OAuth token, they could potentially access those services as if they were you 🥸
With the help of AI, the phishing emails being used are becoming more convincing.
They can appear as document shares, meeting invites, or account notifications, often directing users to legitimate Microsoft sign-in pages.
So, when approval is requested, it doesn’t look or feel suspicious.
That’s the trap 🪤 You approve access on the attacker’s behalf.
This shows how cyber security continues to shift and change over time.
For years, passwords and antivirus software have been the cornerstone of cybersecurity, and they remain essential. However, attackers are now finding ways to bypass them altogether.
In many cases their focus has been to target human behaviour instead.
No hacking required. Just a rushed click, a quick approval, or a moment of distraction. That's often all it takes.
Fortunately, there are things you can do behind the scenes for better protection. Like, configure how Microsoft 365 handles authentication requests.
And raising awareness around unexpected login prompts. A pause when asked to verify or approve access to something often makes all the difference.
So, slow down and think before clicking anything, even if it looks genuine.
👉 Have you noticed that phishing emails are harder to spot lately?



Leave a comment!