Summary
Microsoft has disclosed details of a large-scale credential theft campaign that targeted more than 35,000 users across 13,000 organizations in 26 countries. The sophisticated phishing operation used code-of-conduct-themed lures combined with legitimate email services to redirect victims to attacker-controlled domains and steal authentication tokens.
The phishing emails featured polished, enterprise-style HTML templates with structured layouts and authenticity statements designed to appear highly credible. The campaign primarily targeted organizations in healthcare and life sciences, financial services, professional services, and technology sectors. Microsoft noted this disclosure comes just a month after revealing another large-scale phishing campaign that used device code authentication flows to compromise organizations worldwide.
The scale and sophistication of this campaign demonstrate a clear evolution in phishing tactics — moving beyond crude impersonation toward carefully crafted social engineering that blends seamlessly into everyday business communications.
Source
Commentary
The sheer scale of this campaign — 13,000 organizations across 26 countries — speaks to the industrialization of phishing. These aren’t script kiddies sending poorly formatted emails; this is a professional operation with enterprise-grade tooling and global reach. The use of code-of-conduct-themed lures is particularly insidious because compliance-related emails are exactly the kind of thing employees feel obligated to click on.
The back-to-back disclosures from Microsoft (this campaign plus the device code auth flow campaign from last month) paint a picture of credential theft operating at nation-state scale. Organizations relying solely on user awareness training are fighting the last war. Phishing-resistant MFA — hardware keys, passkeys — is no longer optional for any organization handling sensitive data.
