{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts"},"incident":{"slug":"2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts","title":"Storm-2372 device code phishing campaign hijacks Microsoft 365 accounts","date":"2025-02-13","date_precision":"day","year":2025,"victim_org":"Multiple government, NGO, defence and energy organisations","sector":"Government","country":"Multiple","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Espionage","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Storm-2372 (assessed Russian-aligned)","summary":"Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.","how_it_worked":"The actor built rapport first, messaging targets over WhatsApp, Signal or Teams while posing as a prominent person relevant to the victim's work. It then sent what looked like an invitation to a Teams meeting or a document, containing a genuine Microsoft device code page and a code to type in. Because the sign-in page was real Microsoft infrastructure and the victim entered the code themselves, the flow looked entirely legitimate and MFA prompts appeared expected. Completing it issued the attacker valid access and refresh tokens for the victim's account, giving persistent mailbox and file access without ever handling a password.","lessons":"Disable the device code authentication flow where it is not needed via Conditional Access, and train staff that a legitimate meeting invitation never requires typing a code into a separate sign-in page.","confidence":"Confirmed","sources":[{"title":"Storm-2372 conducts device code phishing campaign","url":"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/","publisher":"Microsoft Security"},{"title":"Phishing campaign targets Microsoft device-code authentication flows","url":"https://www.cybersecuritydive.com/news/phishing-campaign-targets-microsoft-device-code-authentication-flows/740201/","publisher":"Cybersecurity Dive"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-storm-2372-device-code-phishing-campaign-hijacks-microsoft-365-accounts"}}