A recently reported extortion operation shows how voice phishing, device-code login abuse, and rushed MFA enrollment can turn Microsoft 365 identity controls into a pathway for data theft.
A React-based phishing-as-a-service panel reportedly built for Microsoft 365 abuse points to a quieter threat: industrialized token handling, not just stolen passwords.