in

MFA Isn’t Enough as Phishers Use Microsoft Logins to Steal Access

Here’s the ugly truth: multi-factor authentication (MFA) was supposed to be the lock that finally kept thieves out of our online lives. Instead, criminals found a clever way to get us to open the door for them. Recent warnings from the FBI and new analyses from Microsoft and security firms show a sharp rise in attacks that don’t break the tech — they trick the person using it.

What the alerts are saying

Federal and industry teams are sounding the alarm about device-code and OAuth phishing that hands attackers real Microsoft 365 access tokens. The FBI even named a phishing‑as‑a‑service product that automates this trick: Kali365. Microsoft’s security team published a deep dive showing attackers use AI and automation to get victims to complete legitimate sign‑ins. ReliaQuest found groups using vishing plus these token thefts to rip files from SharePoint and extort companies. This isn’t theory — it’s happening now and scaling fast.

How the scam actually works (and why it beats old warnings)

Attackers start a legitimate device‑code login flow and trick the target into entering the short code on Microsoft’s real page. The victim thinks they’re just approving a routine sign‑in. Microsoft then issues valid tokens to the attacker’s session. No fake page. No stolen password. MFA “works” — only it gives the crook a real key. Other versions use push‑spam to wear people down until they tap approve. The result: persistent access that can survive a password change unless tokens are revoked.

Why this matters and who’s vulnerable

This is a human problem as much as a tech one. Criminals now run Phishing‑as‑a‑Service kits and AI tooling that make these attacks cheap and easy. They study how people behave and then weaponize routine tasks. Small businesses, older Americans, and busy employees who approve a prompt without thinking are prime targets. Security remains better with MFA than without it, but these new attacks blunt some of MFA’s best protections.

What to do right now — practical steps

Do not panic, but do act. For organizations: block or restrict device‑code/OAuth flows when not needed via Conditional Access, monitor for strange OAuth activity, and be ready to revoke tokens and sessions immediately on suspicion. Move important accounts to phishing‑resistant MFA — hardware security keys or platform FIDO2 passkeys — and require number‑matching for push approvals. For everyone: treat unsolicited sign‑in requests like a stranger at your door. Don’t type codes from unknown callers or approve random push notifications. Train staff and family to recognize device‑code lures and push fatigue tricks.

Let’s be blunt: technology alone won’t save us. The federal advisories and vendor reports are a reminder that cyber defense is now a shared job between agencies, IT teams, and ordinary users. The good news is there are concrete, proven steps to blunt these attacks. The bad news is that until more people treat an MFA prompt like a real security alarm, the scammers will keep dialing for dollars — now on a subscription plan.

Written by admin

Leave a Reply

Your email address will not be published. Required fields are marked *

Watters: You can't win an election without men

Democrats Bleeding Male Voters as Insurgents Win Primaries

Nancy Guthrie Case Sheriff Says DNA STILL Being Tested

Sheriff Chris Nanos Says DNA Tests Ongoing, Public Demands Answers