Microsoft has disclosed details of a widespread phishing attack that targeted more than 35,000 users across more than 13,000 organizations in 26 countries , using sophisticated social engineering techniques and code of conduct issues. The attack, observed between April 14 and 16, 2026 , is part of a broader trend of increasing sophisticated phishing activity targeting Microsoft 365 environments .
See also: Microsoft: IRS Phishing Attack Hit 29,000 Users with RMM Malware

According to analysis by the Microsoft Defender Security Research Team and Microsoft Threat Intelligence, 92% of targets were located in the United States, with most attacks directed against the healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology-software (11%) sectors.
The phishing emails used highly sophisticated baits related to code of conduct reviews, with display names such as “ Internal Regulatory COC “, “ Workforce Communications “, and “ Team Conduct Report “. The subject lines of the emails included phrases such as “ Internal case log issued under conduct policy “ and “ Reminder: employer opened a non-compliance case log “, creating a sense of urgency and pressure for immediate action.
The technically sophisticated attack approach involved layered corporate-style HTML templates with structured layouts and proactive claims of authenticity. At the top of each message, a notice stated that the message had been “issued through an authorized internal channel” and that links and attachments had been “reviewed and approved for safe access,” reinforcing the apparent legitimacy of the email.
Complex attack chain with MFA bypass techniques
The attack chain directed victims through multiple rounds of CAPTCHAs and intermediate pages designed to give the scheme an appearance of legitimacy while keeping automated defenses at bay. The messages were sent from a legitimate email delivery service and included a PDF that seemingly provided additional information about the ethics review.
See also: Phishing attack targets Apple Pay users

The final phase of the attack led to a login experience that leveraged adversary-in-the-middle (AiTM) phishing techniques to harvest Microsoft credentials and tokens in real time, effectively allowing threat actors to bypass multi-factor authentication (MFA) . The final destination depended on whether the malicious flow was initiated from a mobile device or a desktop system.
This phishing attack is part of a broader context of widespread credential theft campaigns targeting Microsoft 365 environments . In February-March 2026 , Huntress researchers identified an active device code phishing campaign targeting more than 340 Microsoft 365 organizations in the US , Canada , Australia , New Zealand , and Germany .
The revelation comes as Microsoft ’s analysis of the email threat landscape between January and March 2026 revealed that QR code phishing emerged as the fastest-growing attack vector, while CAPTCHA-gated phishing evolved “rapidly” across all payload types. Overall, the tech company said it detected approximately 8.3 billion email phishing threats.
Of these, nearly 80% were link-based, with large HTML and ZIP files accounting for a huge chunk of malicious payloads distributed via phishing emails. The ultimate goal of the vast majority of these attacks was to collect credentials, with malware delivery declining to just 5-6% by the end of the quarter.
Microsoft reported that the operators of the Tycoon 2FA phishing-as-a-service (PhaaS) attempted to change hosting providers and domain registration patterns after a coordinated takedown operation in March 2026.Towards the end of March, Tycoon 2FA moved away from Cloudflare as a hosting service and now hosts most of its domains on various alternative platforms.
See also: Microsoft Recall: Vulnerability exposes decrypted user data

Security experts highlight the sophistication of these campaigns, with the device code phishing technique described as “devious” because it leverages legitimate Microsoft infrastructure . Organizations are advised to implement enhanced email authentication, device code flow monitoring, multi-factor authentication hardening , and regular token and privilege checks to protect against such sophisticated threats, according to the source .
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
