Kaspersky Warns of a Phishing Campaign Abusing Microsoft Authentication Mechanism

Kaspersky has identified a sophisticated phishing campaign that exploits Microsoft's OAuth 2.0 Device Authorization Grant mechanism. Attackers use deceptive emails and fake authentication pages to steal user credentials and maintain account access via stolen refresh tokens.
Why it matters
This highlights a critical security vulnerability in common authentication flows, demonstrating how attackers leverage legitimate enterprise tools to bypass standard security measures.
Kaspersky has released a report about a phishing campaign where attackers abuse Microsoft’s authentication mechanism. The campaign spanned from early April to mid-May 2026 and was styled as a notice from a law firm. The goal was to steal victims’ credentials and access their data. Previously Kaspersky warned about phishing exploiting Google Tasks, Google Forms, Bubble and Amazon Simple Email Service. Microsoft’s authentication mechanism – the OAuth 2.0 Device Authorisation Grant – allows users to log into their Microsoft accounts on devices with limited input capabilities, such as smart TVs, by pasting a code or scanning a QR code on another device, like a smartphone or a PC. This convenience also creates an opportunity for attackers to abuse the flow, potentially hijacking accounts and maintaining control through stolen refresh tokens. Attackers sent victims emails disguised as communication from a law firm, with a password-protected PDF file attached.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in