Hackers exploit Microsoft ADFS in phishing campaign targeting global organizations

itpro.com

A new phishing campaign is targeting organizations using Microsoft’s legacy Active Directory Federation Services (ADFS) to steal login credentials and bypass multi-factor authentication (MFA). Hackers create fake sign-in pages that closely resemble legitimate ADFS portals. The attackers use convincing emails that appear to come from trusted sources, often mimicking IT helpdesk notifications. They also obfuscate URLs to evade detection and dynamically incorporate the victim organization’s branding into the fake login pages. The campaign has affected over 150 organizations, particularly in the education sector, which is more vulnerable due to outdated technology and limited cybersecurity resources. Microsoft recommends transitioning to its modern identity platform, Entra, to enhance security.


With a significance score of 3.6, this news ranks in the top 5.8% of today's 26374 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Hackers exploit Microsoft ADFS in phishing campaign targeting global organizations | News Minimalist