{"id":50406,"date":"2023-02-01T12:57:12","date_gmt":"2023-02-01T12:57:12","guid":{"rendered":"http:\/\/8ad36659-2e77-4ffc-a5ac-c08b32c7d127"},"modified":"2023-02-01T12:57:12","modified_gmt":"2023-02-01T12:57:12","slug":"microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/","title":{"rendered":"Microsoft warning: These phishing attackers used fake OAuth apps to steal email"},"content":{"rendered":"<figure class=\"c-shortcodeImage u-clearfix c-shortcodeImage-large\">\n<div class=\"c-shortcodeImage_imageContainer\">\n<div class=\"c-shortcodeImage_image\"><picture class=\"c-cmsImage c-cmsImage_loaded\"><source media=\"(max-width: 767px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/23e2d2c937e3e83801e0de1fcc903bf28197a541\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=768\" alt=\"looking-at-pc\"><source media=\"(max-width: 1023px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/5b00b615a1480f8589446e61b116c1d5ef9280a3\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1024\" alt=\"looking-at-pc\"><source media=\"(max-width: 1440px)\" srcset=\"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280\" alt=\"looking-at-pc\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280\" alt=\"looking-at-pc\" width=\"1280\" height=\"851.7247879359095\" fetchpriority=\"low\"><\/picture><\/div>\n<p> <!----><\/div>\n<p> <!----><figcaption> <span class=\"c-shortcodeImage_credit g-outer-spacing-top-xsmall u-block\">Image: Getty Images<\/span><\/figcaption><\/figure>\n<p>Microsoft has warned that fraudulent Microsoft Partner Network (MPN) accounts were used in a phishing campaign that featured bogus apps that tricked victims into granting them permissions to access their email accounts.&nbsp;<\/p>\n<p>The attackers used the fraudulent MPN accounts to register fake versions of legitimate-sounding apps, such as &#8220;Single Sign On (SSO)&#8221; and &#8220;Meeting&#8221; that were dressed up with convincing visual indicators, including Zoom&#8217;s older video icon and and Zoom-like URLs, <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/cloud-security\/dangerous-consequences-threat-actors-abusing-microsofts-verified-publisher\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">according to security firm Proofpoint<\/a>.<\/p>\n<p><strong>Also: <\/strong><a href=\"https:\/\/www.zdnet.com\/article\/connecting-to-public-wi-fi-heres-how-to-protect-your-data-and-your-device\/\" rel=\"follow\"><strong>Public Wi-Fi safety tips: Protect yourself against malware and security threats<\/strong><\/a><\/p>\n<p>The attackers first impersonated legitimate companies to enroll in the Microsoft Cloud Partner Program or MCCP (formerly known as Microsoft Partner Network or MPN), and then used the accounts to add a verified publisher to OAuth app registrations, which they created in Azure Active Directory (AD).&nbsp;<\/p>\n<p>Microsoft classifies the attack as &#8220;consent phishing&#8221; because the attackers use the bogus apps and Azure AD-based OAuth consent prompts (pictured below) to trick targets to grant permissions to the app, for example, to read emails, access contacts, and so on, potentially for an entire year. Also, with verified publisher status, the publisher name gains a blue &#8216;verified&#8217; badge that signals Microsoft has verified the publisher of the app.&nbsp;<\/p>\n<div class=\"c-shortcodePinbox-textList c-shortcodePinbox-textList_floating g-border-thin-light-bottom g-outer-spacing-top-medium g-outer-spacing-bottom-medium\">\n<h3 class=\"c-sectionHeading\">More Microsoft<\/h3>\n<\/p><\/div>\n<p>Microsoft <a href=\"https:\/\/msrc-blog.microsoft.com\/2023\/01\/31\/threat-actor-consent-phishing-campaign-abusing-the-verified-publisher-process\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">says in a blogpost<\/a> that the phishing campaign targeted &#8220;a subset of customers primarily based in the UK and Ireland&#8221;. It has also disabled the fraudulent apps and notified affected customers.&nbsp;<\/p>\n<p>Microsoft has seen consent phishing incidents <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-warns-about-this-phishing-attack-that-wants-to-read-your-emails\/\" rel=\"follow\">increase steadily in recent years<\/a>, where the technique has been used to target Office 365 customers. Once granted by a victim, OAuth permission tokens are useful because the attacker doesn&#8217;t require the target&#8217;s account password, but can still access confidential data. Microsoft recently <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/active-directory\/manage-apps\/protect-against-consent-phishing\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">updated its document<\/a> about the style of attack.<\/p>\n<p>Proofpoint detected the malicious third-party OAuth apps on December 6 and informed Microsoft on December 20. It notes the phishing campaign ended on December 27. Microsoft became aware of the consent-phishing campaign on December 15. &nbsp; &nbsp;<\/p>\n<p>Proofpoint highlights consent phishing for OAuth delegated permissions as a powerful tool that can allow the malicious app to act on the user&#8217;s behalf &#8212; accessing mailbox resources, calendar, and meeting invitations linked to compromised user accounts. &nbsp;<\/p>\n<p>&#8220;The granted token (refresh token) has a long expiry duration of over a year in most cases. This gave threat actors access to the compromised account&#8217;s data and the ability to leverage the compromised Microsoft account in subsequent BEC or other attacks,&#8221; it notes.<\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/home-and-office\/work-life\/cybersecurity-staff-are-struggling-heres-how-to-support-them-better\/\" rel=\"follow\"><strong>Cybersecurity staff are struggling. Here&#8217;s how to support them better<\/strong><\/a><\/p>\n<p>Microsoft determined the primary goal in this campaign was to exfiltrate a target organization&#8217;s email.&nbsp;<\/p>\n<p>&#8220;Microsoft&#8217;s investigation determined that once consent was granted by victim users, threat actors used third-party OAuth applications as a primary technique\/vector to exfiltrate email. All impacted customers whose users granted consent to these applications have been notified,&#8221; it notes. &nbsp; &nbsp;<\/p>\n<p>So, how did the threat actors get past Microsoft&#8217;s checks for MPN\/MCPP? According to Proofpoint, the actors displayed one name on their fraudulent apps that looked like the name of an existing legitimate publisher. Meanwhile, they hid the actual &#8220;verified publisher&#8221; name, which was different to the displayed name. Proofpoint notes that, in two cases, the actors got verification just one day after they created the malicious application. &nbsp;<\/p>\n<p>Once the attacker got a verified publisher ID, they also added links in each app to the &#8220;terms of service&#8221; and &#8220;policy statement&#8221; of the impersonated organization&#8217;s website. In the past, consent-phishing campaigns have compromised existing MPN verified publishers to abuse OAuth. The new method enhances the credibility of the malicious OAuth apps.&nbsp;<\/p>\n<p>Microsoft says it has &#8220;implemented several additional security measures to improve the MCPP vetting process and decrease the risk of similar fraudulent behavior in the future.&#8221;&nbsp;<\/p>\n<figure class=\"c-shortcodeImage u-clearfix c-shortcodeImage-large\">\n<div class=\"c-shortcodeImage_imageContainer\">\n<div class=\"c-shortcodeImage_image\"><picture class=\"c-cmsImage\"><!----> <img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/\" alt=\"picture7\" width=\"1280\" height=\"1721.5412844036698\" fetchpriority=\"low\"><\/picture><\/div>\n<p> <!----><\/div>\n<p> <!----><figcaption> <span class=\"c-shortcodeImage_credit g-outer-spacing-top-xsmall u-block\">Image: Proofpoint<\/span><\/figcaption><\/figure>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phishing attackers bypassed Microsoft&#8217;s verified publisher checks to create apps that dupe victims into granting access to their online accounts.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-50406","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft warning: These phishing attackers used fake OAuth apps to steal email 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft warning: These phishing attackers used fake OAuth apps to steal email 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-01T12:57:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Microsoft warning: These phishing attackers used fake OAuth apps to steal email\",\"datePublished\":\"2023-02-01T12:57:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/\"},\"wordCount\":663,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\\\/2023\\\/02\\\/01\\\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\\\/looking-at-pc.jpg?auto=webp&amp;width=1280\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/\",\"name\":\"Microsoft warning: These phishing attackers used fake OAuth apps to steal email 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\\\/2023\\\/02\\\/01\\\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\\\/looking-at-pc.jpg?auto=webp&amp;width=1280\",\"datePublished\":\"2023-02-01T12:57:12+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\\\/2023\\\/02\\\/01\\\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\\\/looking-at-pc.jpg?auto=webp&amp;width=1280\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/a\\\/img\\\/resize\\\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\\\/2023\\\/02\\\/01\\\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\\\/looking-at-pc.jpg?auto=webp&amp;width=1280\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft warning: These phishing attackers used fake OAuth apps to steal email\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft warning: These phishing attackers used fake OAuth apps to steal email 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft warning: These phishing attackers used fake OAuth apps to steal email 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-02-01T12:57:12+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Microsoft warning: These phishing attackers used fake OAuth apps to steal email","datePublished":"2023-02-01T12:57:12+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/"},"wordCount":663,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/","url":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/","name":"Microsoft warning: These phishing attackers used fake OAuth apps to steal email 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280","datePublished":"2023-02-01T12:57:12+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#primaryimage","url":"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280","contentUrl":"https:\/\/www.zdnet.com\/a\/img\/resize\/ae2b49e47e6c10b4bc19e28caf769aa73ce00c07\/2023\/02\/01\/7bf3b9eb-7651-49e7-bebd-4366eb7faba8\/looking-at-pc.jpg?auto=webp&amp;width=1280"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-warning-these-phishing-attackers-used-fake-oauth-apps-to-steal-email\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Microsoft warning: These phishing attackers used fake OAuth apps to steal email"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=50406"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50406\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=50406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=50406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=50406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}