#MFA bypass
13 stories taggedMFA bypass.

NovaCookies Phishing Kit Rents Microsoft 365 Session Theft for $320 a Month
A new subscription phishing service abuses genuine Docusign emails to slip past multi-factor authentication and steal live Microsoft 365 logins.

Mirage2FA Phishing Kit Slipped Past Microsoft 365 Logins at 4,500 Firms
A rented phishing service quietly harvested Microsoft 365 credentials and two-factor codes across US and European companies for nearly two years.

Fake Job Interviews Are Stealing Google and Facebook Logins
A phishing operation called RecruitTrap uses realistic pop-up windows to grab passwords and even one-time codes from job seekers.

Greatness Phishing Kit Adds a New Trick to Steal Logins Without Passwords
The rented phishing toolkit now abuses Microsoft's own login flow to walk around multi-factor authentication.

Changing Your Password No Longer Kicks Hackers Out
A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

Insurance phishing gets faster: attackers now hijack accounts in real time
Researchers say fake insurance login pages are being run live, with criminals stepping in the moment a victim types their password.

German Police Shut Down Kratos Phishing Network, But Experts Say the Pause Will Be Brief
Authorities seized more than 200 servers and arrested a developer in Indonesia. Security researchers say the 1,800 customers who used the service are already shopping for a replacement.

Police shut down Kratos, the phishing kit built to hijack Microsoft 365 logins
German and US investigators dismantled the kit's servers, and Indonesian police arrested its alleged creator, ending a service that helped criminals slip past two-factor login checks.

A Phishing Crew Forgot to Lock Its Own Front Door
A single sloppy command in a shell history file handed French researchers the full toolkit behind three live Microsoft 365 phishing operations.

Two Scattered Spider Members Plead Guilty as London Trial Opens
Thalha Jubair and Owen Flowers admitted roles in the TfL intrusion and a sprawling SIM-swap and SMS-phishing operation that turned harvested SSO credentials into nine-figure ransom payouts.

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.
Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA
The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

FBI flags Kali365, the latest phishing kit pitched at draining Microsoft 365 tenants
The bureau says the subscription-priced service abuses OAuth device-code flows to lift session tokens and walk straight past MFA.