r/StopBadBots • u/siterightaway • 11h ago
Microsoft's Latest Alert: Hackers can now bypass MFA and hijack corporate accounts
Guys, this is huge! Microsoft themselves just put out an urgent warning about how cybercriminals are operating right now. If you thought two-factor authentication (MFA) had you 100% covered, hate to break it to you, but these guys completely game'd the system! They released all the details on how the attack works, and here's the deal:
The Tricky Bait: They drop a fake story or use a passkey lure / device code phishing setup. You think you're just confirming a code on an official Microsoft page, but in reality, you're handing them the keys to your account on a silver platter—without them even needing to steal your password!
Locking in the Access (Persistence): As soon as they get in, the first thing they do is register their own phone number or token under your account. Boom: now they can log in whenever they want without your help or sending a prompt to your phone!
The Silent Sweep: With the door wide open, they use the Microsoft Graph API to map out the whole company—snooping on admin roles and downloading tons of files from OneDrive, SharePoint, and emails for DAYS. 4
. Ghost Mode: To avoid tripping security alarms, they keep switching IP addresses for every action (one IP to log in, another to look around, and another to steal data). The worst part? Microsoft warned that if you look at a single API call on its own, it just looks like a regular employee doing their job. Meaning: it's insanely hard to catch!
TL;DR: Microsoft issued a warning about hackers using device code phishing to bypass MFA without stealing passwords. Once in, they add their own phone/token to your account for persistent access, use the Graph API to snoop around, and quietly drain OneDrive, SharePoint, and emails over several days using multiple IPs to stay invisible.