< ciso
brief />
Tag Banner

All news with #mfa fatigue tag

53 articles

ReliaQuest: ShinyHunters Social Engineering Incident

🛡️ ReliaQuest disclosed a social engineering campaign by ShinyHunters that briefly exposed its identity dashboard but said claims of a compromise or ransomware targeting are false. The attacker used a lookalike domain and fake SSO page, convincing one employee to approve a push and gain a brief, view-only session. ReliaQuest emphasized robust controls—device trust, session termination, password expiry and auth resets—prevented access to applications or customer data.
read more →

Phishing service spoofs RingCentral to steal Microsoft 365

📧 The Greatness phishing-as-a-service platform has expanded to adversary-in-the-middle and device-code phishing targeting Microsoft 365 users across several countries. Operators abused RingCentral to bypass filters by leveraging whitelisting and fraudulent verification banners to lower suspicion. Victims were routed to AiTM or device-code flows that captured MFA-approved tokens, enabling long-lived access to mailboxes, Teams, SharePoint, OneDrive, and more.
read more →

Why device code phishing became an industrial threat

🔒 Device code phishing — the abuse of the OAuth 2.0 device authorization grant — has rapidly evolved from a niche red-team tactic into a widespread criminalized attack. Exploiting the authorization step after authentication, it defeats all forms of MFA and has been commercialized in phishing-as-a-service kits. Push Security researchers outline the attack mechanics, ecosystem growth, cross-platform risk, and detection challenges for defenders.
read more →

How attackers bypass multifactor authentication risks

🔒 This article examines prevalent methods attackers use to bypass multifactor authentication (MFA), from MFA fatigue and social engineering to cookie theft and targeting weak or non‑MFA accounts. It summarizes survey findings on uneven MFA adoption, highlights real-world incidents (Okta, Uber), and notes industry guidance favoring phishing‑resistant and passwordless approaches. The piece concludes with concrete defensive steps such as adaptive authentication, tightening access rights, and reviewing password reset workflows.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

First-person identity theft and email risk

🛡️ Harrowing first-person account of identity theft highlights how a single mistake—sharing a two-factor authentication code—enabled a scammer to seize the victim's email. The piece underscores that many online accounts are effectively secured by email access, making email compromise catastrophic. It emphasizes practical lessons about account recovery, 2FA methods, and attacker behaviors.
read more →

Authorities dismantle major Kratos phishing infrastructure

🛡️ German and US law enforcement dismantled the core infrastructure of the Kratos phishing kit and arrested a developer in Indonesia. Investigators disabled over 200 servers; authorities estimate about 1,800 customers ran roughly 15,000 phishing campaigns per month. Kratos stole credentials and session cookies, enabling adversary-in-the-middle bypasses of MFA and persistent access to Microsoft 365 accounts.
read more →

Helix vishing group targets SharePoint data theft

🔒 A new extortion group dubbed Helix uses vishing, device-code phishing, and MFA abuse to access and exfiltrate files from SharePoint environments. Operators impersonate managers via phone calls and spoofed caller IDs to trick employees into granting access, then register authenticators for persistence and bulk-download content. ReliaQuest links Helix tactics and infrastructure to prior groups like ShinyHunters and BlackFile, and recommends disabling device-code authentication and restricting SharePoint to managed devices.
read more →

Phishing campaign abused Facebook verification claims

🔒 Cybercriminals abused Facebook Messenger chatbots to deliver phishing messages that appeared to come from legitimate Facebook Business accounts. The campaign, active from November 2025 until June 2026, coaxed victims to log in on fake pages and surrender credentials, MFA codes, contact details and images of government IDs. Meta disrupted the infrastructure after Huntress reported the activity, but business accounts remain attractive targets.
read more →

EvilTokens phishing abuses OAuth device code flow

🛡️ EvilTokens is a phishing-as-a-service kit that compromises Microsoft 365 accounts by abusing the OAuth 2.0 device authorization grant flow, tricking victims into authorizing attacker sessions via legitimate Microsoft login pages. Active since at least February 2026, the toolkit has been used in large account takeover and BEC campaigns, leveraging reconnaissance and decoy lures to obtain access and refresh tokens. Because victims complete real authentication — including 2FA — the attacks bypass traditional red flags like fake login pages. Organizations are advised to restrict device code flow, monitor unusual token activity, and update security awareness to address these modern phishing tactics.
read more →

Dashlane reports brute-force compromise of few vaults

🔐 Dashlane disclosed a brute-force attack on May 31, 2026, targeting certain personal accounts to bypass two-factor authentication and register new devices. Its security controls triggered temporary suspensions and authentication issues, and although access has been restored, attackers succeeded in downloading encrypted vaults for fewer than 20 personal-plan users. Dashlane stressed that vault contents remain protected by each user's Master Password and that its internal systems were unaffected.
read more →

FBI Alerts on Kali365 Phishing Service Targeting M365

🔒 The FBI warns about the Kali365 phishing-as-a-service platform that abuses OAuth device code authentication to hijack Microsoft 365 and Microsoft Entra accounts. Distributed via Telegram since April 2026, Kali365 enables low-skilled attackers to bypass MFA by tricking victims into authorizing device codes, then capturing OAuth tokens to access mailboxes and cloud apps. Researchers observed campaigns using phishing emails, AI-generated lures, and real-time dashboards, while the FBI advises blocking device code flows and preserving forensic evidence.
read more →

FBI Warns of Kali365 Phishing-as-a-Service Threat

🛡️ The FBI has identified a new phishing-as-a-service platform called Kali365, first seen in April 2026, that is being distributed primarily via Telegram. The service furnishes AI-generated lures, automated templates and real-time tracking dashboards to enable attackers — including low-skill actors — to capture OAuth tokens and bypass MFA for Microsoft 365 accounts. Victims are tricked into pasting device codes into the legitimate Microsoft verification page, unintentionally authorizing attacker devices and granting persistent access to services such as Outlook, Teams and OneDrive. The FBI recommends restricting or blocking device code flow, implementing conditional access policies, blocking authentication transfer and protecting emergency access accounts.
read more →

Storm-2949: Identity Compromise Leads to Cloud Breach

🔐 Microsoft Threat Intelligence details how Storm-2949 converted targeted identity compromise into a broad cloud breach, exfiltrating data from Microsoft 365 and production workloads in Azure. The actor abused SSPR-based social engineering to bypass MFA, performed directory discovery via Graph API, and leveraged management-plane operations to retrieve Key Vault secrets and download large volumes of data. Organizations should adopt behavior-based detections such as Microsoft Defender and tighten RBAC and administrative controls to detect and mitigate similar identity-driven cloud attacks.
read more →

BlackFile (UNC6671): Vishing and SSO extortion campaign

🔐 Google Threat Intelligence Group (GTIG) details UNC6671, operating as "BlackFile," which uses large-scale voice phishing (vishing) and adversary-in-the-middle techniques to bypass MFA and compromise SSO access. The group targets Microsoft 365 and Okta, leveraging Python and PowerShell scripts to automate exfiltration and repurpose valid session cookies to "stream" files. GTIG highlights detection indicators such as python-requests User-Agent mismatches, nonstandard IP infrastructure, and subdomain-based credential-harvesting sites to aid defenders.
read more →

FlowerStorm Phishing Adopts Browser VM Obfuscation

🔒 Researchers at Sublime Security reported that the FlowerStorm phishing-as-a-service campaign has begun using KrakVM, an open-source browser-based JavaScript virtual machine, to conceal credential-stealing code inside HTML attachments. When victims open the attachments in a browser, encrypted bytecode is executed by the VM and launches a dynamic credential- and MFA-harvesting workflow. The kit supports real-time AiTM interception and adapts phishing pages to the victim’s provider and branding, complicating static analysis and many email defenses.
read more →

MuddyWater Employs Microsoft Teams for Targeted Intrusion

🔐 Rapid7 attributes a deception-driven intrusion to the Iranian-affiliated actor MuddyWater, which used Microsoft Teams social engineering to harvest credentials and manipulate MFA via live screen-sharing. Once inside, operators leveraged compromised accounts, remote-access tools like DWAgent and AnyDesk, and a trojanized WebView2 binary to maintain persistence and exfiltrate data rather than encrypt files. The campaign appears to have intentionally mimicked RaaS artefacts — including Chaos-related extortion indicators and a signed loader — to obscure state-backed motives and slow incident response.
read more →

Microsoft details large-scale credential theft phishing

🔒 Microsoft disclosed a large-scale credential-theft phishing campaign that ran April 14–16, 2026, targeting over 35,000 users at more than 13,000 organizations across 26 countries. Attackers used polished, code-of-conduct-themed HTML lures, legitimate email delivery services and PDF attachments to funnel victims through CAPTCHA-gated pages into AiTM sign-in flows that harvested credentials and tokens, bypassing MFA. Most targets were in the U.S., with heavy impacts on healthcare, finance, professional services, and technology. Microsoft linked many endpoints to Tycoon 2FA, with additional activity tied to Kratos and EvilTokens.
read more →

BlackFile Extortion Group Targets Retail and Hospitality

📞 Unit 42 and RH-ISAC report BlackFile has targeted retail and hospitality since Feb 2026, linking activity to CL-CRI-1116 and overlaps with UNC6671/Cordial Spider. The group uses vishing—impersonating IT helpdesks with spoofed VoIP—and phishing pages that mimic corporate SSO, plus antidetect browsers and residential proxies to harvest credentials and OTPs. After access they register devices to bypass MFA, escalate privileges, and exfiltrate data via Salesforce and SharePoint APIs. Recommendations include caller identity checks, strict escalation for IT support, and simulation-based phone-security training.
read more →

FBI and Indonesia Dismantle W3LL Phishing Platform

🔒 The FBI Atlanta Field Office and Indonesian authorities dismantled the W3LL phishing platform and seized infrastructure, leading to the arrest of the alleged developer. The W3LL kit, sold for $500, enabled adversary-in-the-middle attacks to capture credentials, session cookies and one-time MFA tokens, allowing attackers to bypass multifactor protections. Its marketplace, W3LLSTORE, facilitated the sale of over 25,000 compromised accounts and contributed to attempts exceeding $20 million in fraud.
read more →