News and Knowledge Portal for Identity Verification Professionals

collapse
...
Home / Fraud / Microsoft flags phishing campaign abusing Entra ID, Google OAuth links
Microsoft flags phishing campaign abusing Entra ID, Google OAuth links

Microsoft flags phishing campaign abusing Entra ID, Google OAuth links

2026-03-02  Per Henrikson

The threat actors create malicious OAuth apps and distribute crafted OAuth URLs via email that may evade email defenses due to the use of legitimate domains such as login.microsoftonline.com and accounts.google.com. Email lures include fake e-sign documents, Social Security notices, Teams meeting recordings, password reset prompts and employee review documents.


Share: