Your MFA Isn't Enough. (And Most Places Don't Even Have That.)

A phishing campaign bypassed MFA at 340+ organizations using legitimate OAuth flows, while 76% of companies are still relying on passwords in the first place.

Read More

340+ Organizations Hit by M365 Phishing That Bypasses MFA Without Touching Your Password

A device code OAuth phishing campaign has compromised 340+ organizations since February 2026, bypassing MFA and surviving password resets. It's still running.

Read More