Device Code Phishing Campaign Targets Microsoft 365: What Businesses Need to Know

By Sentaro Team ยท Published March 26, 2026

A phishing campaign exploiting OAuth is targeting Microsoft 365 users across several countries. Learn why it matters and how to protect your business.

What Happened

A recent cybersecurity alert has brought to light a device code phishing campaign targeting Microsoft 365 identities. This campaign has impacted over 340 organizations across the United States, Canada, Australia, New Zealand, and Germany. The attackers are exploiting OAuth to deceive users into granting permissions that could compromise their accounts.

Why It Matters

This phishing campaign is significant for several reasons:

What to Do Next

Businesses can take several steps to protect themselves from this and similar threats:

Key Takeaways

FAQ

What is OAuth, and how is it being abused?

OAuth is an open standard for access delegation, commonly used for token-based authentication. Attackers abuse it by tricking users into granting permissions, allowing them access without direct credentials.

How can businesses detect OAuth abuse?

Businesses can detect OAuth abuse by monitoring OAuth activity logs, setting up alerts for unusual permission requests, and regularly reviewing third-party app permissions.

Why is multi-factor authentication important?

MFA adds an extra layer of security by requiring a second form of verification, making it harder for attackers to gain unauthorized access even if they have a user's password.

At Sentaro, we understand the critical importance of cybersecurity in today's digital landscape. By staying informed and proactive, you can protect your business from emerging threats. Visit Sentaro for more insights and solutions tailored to your security needs.