OAuth token theft surges as attackers weaponise consent
Account takeover is now perpetrated by hijacking trusted workflows, even in environments where multi-factor authentication is switched on.
The incidence of OAuth token theft is on the rise, as cybercriminals exploit phishing campaigns to weaponize consent and gain unauthorized access to Microsoft 365 and other cloud platforms. Traditional methods of defending against account takeover, such as cracking weak passwords, are no longer sufficient. Instead, attackers focus on hijacking trusted workflows that appear legitimate, even in environments where multi-factor authentication (MFA) is already enabled.
These attacks are specifically designed for organizations that have implemented MFA, shifting the focus from credential theft to abuse of consent and identity workflows. According to Microsoft, there are approximately 600 million identity-based attacks against its customers each day. Additionally, billions of phishing emails globally are now targeted at compromising identities rather than just endpoints.
The technique involves attackers registering malicious OAuth applications and initiating legitimate device authorization flows on Microsoft infrastructure. They create convincing emails that appear to come from trusted brands, such as Microsoft, DocuSign, and Mimecast itself, requesting users to authenticate a device or access a document using a code. When victims enter the code on the real Microsoft device login page, they inadvertently grant the attacker's app persistent access to their account.
Attackers can then use the long-lived OAuth token to perform various malicious activities, such as reading and sending emails, accessing documents, manipulating collaboration tools, and exfiltrating data—all without needing a password. Mimecast's researchers have observed attackers mimicking the company's own device enrollment experience, displaying fake Mimecast branding and a "Get Authentication Code" button, which refreshes the page and reveals a code directly in the browser.
However, Mimecast's legitimate device enrollment process never shows codes on a webpage; instead, they are delivered via email and entered into a dedicated verification field.
Once an attacker obtains the token, the impact can be extensive, as they can read and send emails, access documents, manipulate collaboration tools, and exfiltrate data without triggering traditional credential-based alerts. The access appears to be authorized, so many legacy controls treat the activity as routine, failing to detect the malicious behavior.
The solution lies in connecting fragmented signals into a unified view, implementing a platform that can join the dots between the email delivering the device code, the browser session that follows multiple redirects, the consent granted to a suspicious app, and the subsequent behavioral anomalies and data movements. This end-to-end visibility is crucial for detecting account takeover in plain sight.
Organizations should treat identity workflows and consent prompts as critical security controls, not background noise. By combining advanced pre-click inspection of URLs, real-time protection around credential and consent events, post-compromise behavioral analytics, and data exfiltration monitoring into a single, coordinated defense, organizations can better protect against this evolving threat.
Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.