State Actors Abuse OAuth Device Codes to Gain Full Access to M365 Account: Here’s What We Know


  • Proofpoint reports increase in phishing abusing Microsoft OAuth 2.0 device code flow
  • Victims enter codes on real Microsoft domains, granting access tokens to attackers
  • Proofpoint advises blocking device code streams

Cybercriminals, including state-sponsored threat actors, are increasingly abusing Microsoft’s OAuth 2.0 device passcode authentication flow to take over Microsoft 365 accounts.

That’s according to a new report from cybersecurity researchers Proofpoint. In a new paper published on December 18, researchers confirm that there has been a sharp escalation in social engineering attacks since September 2025, in which victims are tricked into granting access to their accounts.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top