This Cyber Attack Targets Microsoft 365 Accounts
A new cyberattack is targeting Microsoft 365 users through Signal and WhatsApp messages, with hackers impersonating government officials in order to gain access to accounts. According to reporting from Bleeping Computer, bad actors—who are believed to be Russians pretending to be European political officials or diplomats—are contacting employees of organizations working on issues related to Ukraine and human rights. The end goal is to trick targets into clicking an OAuth phishing link leading them to authenticate their Microsoft 365 credentials. This scam, first discovered by cybersecurity firm Volexity, has focused specifically on organizations related to Ukraine, but a similar approach could be used more widely to steal user data or take over devices. How the Microsoft 365 OAuth attack w...










