HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Global Phishing Campaign Hijacks Auth Tokens from 35K Users Across 26 Countries

Microsoft reported a sophisticated phishing operation that stole authentication tokens from over 35,000 users in 26 countries, mainly U.S. healthcare and finance. The attack bypassed MFA by using an adversary‑in‑the‑middle flow, highlighting a critical credential‑theft risk for third‑party identity providers.

LiveThreat™ Intelligence · 📅 May 05, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Global Phishing Campaign Hijacks Auth Tokens from 35K Users Across 26 Countries

What Happened — Microsoft disclosed a sophisticated phishing operation that compromised authentication tokens from more than 35,000 users in 26 nations, primarily the United States. Attackers leveraged fake “code‑of‑conduct” emails, PDF attachments, and an adversary‑in‑the‑middle (AiTM) flow to capture tokens even when MFA was enabled.

Why It Matters for TPRM

  • Credential theft bypasses traditional MFA, exposing downstream SaaS and cloud services.
  • The use of legitimate email delivery platforms makes detection harder for third‑party security controls.
  • Affected sectors (healthcare, finance) often host sensitive PII, raising downstream breach risk for their vendors.

Who Is Affected — Healthcare providers, financial institutions, and any organization using Microsoft Azure AD or similar identity services.

Recommended Actions — Review authentication and MFA configurations with vendors, enforce anti‑phishing training, deploy advanced email threat protection, and monitor for anomalous token usage.

Technical Notes — Attack vector: phishing emails with PDF links → Cloudflare CAPTCHA → fake Microsoft sign‑in page → AiTM token capture. No specific CVE. Data stolen: OAuth/SAML authentication tokens granting direct account access. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/191695/security/microsoft-warns-of-global-campaign-stealing-auth-tokens-from-35k-users.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.