A particularly sophisticated phishing campaign has emerged that effectively bypasses multi-factor authentication, putting users of the Microsoft 365 and Okta platforms and, by extension, the organizations that rely on them for identity management at serious risk.
See also: Microsoft investigates Defender Portal access issues

The campaign, detected in early December 2025, demonstrates a deep understanding of certification mechanisms.
The attacks target businesses across a variety of industries through highly convincing phishing emails, which appear to be HR or benefits-related notifications. Security analysts at Datadog Security Labs spotted this active campaign, which focuses on organizations using Microsoft 365 and Okta for single sign-on services.
Attackers are leveraging modern phishing techniques that intercept legitimate SSO flows, allowing them to extract both user credentials and session tokens before MFA can prevent unauthorized access.
At the same time, they have registered a number of similar domains, such as sso.okta-secure.io, sso.okta-cloud.com and sso.okta-access.com, creating highly convincing copies of the authentic certification pages.
See also: Microsoft: Investigating Copilot issue regarding file editing

The phishing emails, which are sent from compromised accounts connected to Salesforce Marketing Cloud, use salary-related bait, such as annual salary reviews and bonus information.
The messages contain shortened links that take victims to original phishing websites, which are hosted on Cloudflare infrastructure. In recent weeks, organizations have reported that hundreds of users across various companies have received these emails, with the campaign remaining active until December 2025.
The attack operates through a two-stage phishing process that leverages JavaScript to steal credentials. In the first stage, the attackers forward legitimate Okta pages through a proxy, while embedding malicious code that logs usernames and monitors for session cookies. The embedded inject.js script continuously monitors certain critical cookies — such as idx, JSESSIONID, proximity_, DT , and sid — that are essential for maintaining active sessions.
See also: Microsoft sued for misleading millions of Microsoft 365 subscribers

Every second, the script checks for new or modified cookies and sends them to the attacker's server via POST request to the /log_cookie endpoint, allowing the attacker to replay the victim's session in their own browser.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
