North America
Microsoft users
Microsoft disclosed details of a large-scale credential theft campaign that targeted more than 35,000 users across 13,000 organizations in 26 countries.
The campaign used code-of-conduct-themed phishing lures, combined with legitimate email services, to redirect users to attacker-controlled domains and steal authentication tokens. The phishing emails featured polished, enterprise-style HTML templates with structured layouts and authenticity statements, making them appear more credible and convincing than typical phishing attempts.
Most of the phishing emails targeted organizations in the health care and life sciences, financial services, professional services and technology sectors. The disclosure comes just a month after Microsoft revealed another large-scale phishing campaign using device code authentication flows to compromise organizations worldwide.
How it could affect your business
Today's phishing campaigns are becoming increasingly sophisticated, blending seamlessly into everyday business communications and making them harder for users to identify. Organizations should prioritize continuous user awareness training and leverage advanced technologies, such as GenAI, to detect and stop evolving phishing threats.