{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T08:17:50.942Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365","title":"Exposed server reveals three Evilginx operations phishing Microsoft 365 accounts","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Corporate Microsoft 365 users across a dozen countries","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Actors tracked as codemado, mail-argenta and saroula01","summary":"French security firm Lexfo found a misconfigured server in Budapest in late April 2026 that exposed the operations of three separate actors running custom forks of the Evilginx reverse proxy against Microsoft 365. The findings were published in July 2026. One operator, saroula01, captured 218 distinct accounts between June 2025 and July 2026, roughly 94 percent of them corporate mailboxes across a dozen countries, using Microsoft's device code sign-in flow rather than proxy interception. One stolen cookie carried an expiry of 30 June 2027.","how_it_worked":"Two of the three crews ran reverse-proxy phishing: the victim received a link to a page that forwarded every keystroke to the real Microsoft login and returned the genuine responses, so the sign-in looked and behaved correctly while the operator captured the password and the resulting session cookie. The mail-argenta fork pre-filled the victim's email address and rewrote URLs to evade detection. The quietest and most successful operator instead abused Microsoft's legitimate device code flow, persuading targets to enter a short code on the real Microsoft site, which authorises the attacker's device without any fake page at all and defeats MFA including passkeys.","lessons":"Device code flow should be disabled by conditional access policy where it is not needed, and long-lived session cookies should be cut short and rebound to device compliance.","confidence":"Confirmed","sources":[{"title":"Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365","url":"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html","publisher":"The Hacker News"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-exposed-server-reveals-three-evilginx-operations-phishing-microsoft-365"}]}