HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Forg365 Phishing‑as‑a‑Service Hijacks Microsoft 365 Sessions via Device‑Code and AitM Tactics

A new PhaaS called Forg365 sells a chain that abuses Microsoft 365’s device‑code flow and performs AitM session theft, exposing organizations to credential compromise. The attack highlights gaps in SOC 2 access‑control and security‑awareness controls that continuous‑compliance programs must address.

LiveThreat™ Intelligence · 📅 July 13, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Forg365 Phishing‑as‑a‑Service Hijacks Microsoft 365 Sessions with Device‑Code and AitM Tactics

What Happened — A new Phishing‑as‑a‑Service (PhaaS) called Forg365 is selling a turnkey attack chain that abuses Microsoft 365’s device‑code flow and performs adversary‑in‑the‑middle (AitM) session hijacking. The service, advertised on Telegram for $400 /month, combines AI‑generated lures, anti‑bot evasion, and post‑compromise mailbox manipulation to steal credentials and maintain persistent access.

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC 6.2 (Logical Access Controls) and CC 7.1 (Security Awareness & Training) – controls designed to prevent credential compromise and to detect anomalous authentication flows.
  • Continuous evidence of MFA enforcement, conditional‑access policies, and user‑behavior analytics can serve as audit‑ready proof that the organization mitigates phishing‑derived credential theft.

Who Is Affected — Enterprises and service providers that rely on Microsoft 365 for email, collaboration, and identity management (technology, finance, healthcare, education, etc.).

Recommended Actions

  • Enforce MFA and conditional‑access policies that block device‑code grant types for high‑risk users.
  • Deploy real‑time security awareness training that includes device‑code phishing simulations.
  • Enable Azure AD sign‑in risk detection and log analytics to flag abnormal token exchanges.
  • Regularly review privileged mailbox activity for signs of post‑compromise mailbox operations.

Source: The Hacker News

Technical Notes

  • Attack vector: Device‑code phishing → AitM session hijack → mailbox takeover.
  • Tools: Telegram‑based service marketplace, AI‑generated phishing lures, custom scripts to intercept OAuth device‑code tokens.
  • Data at risk: User credentials, email content, calendar data, and any downstream SaaS integrations accessed via the compromised Microsoft 365 session.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/forg365-phaas-targets-microsoft-365.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →