💻 techEvent0 views3 min read

What Happened to Microsoft 365 Link-Based Hacking Incidents and Phishing Campaigns?

The 'Windows 365 Link Hacking Incident' refers to a persistent and evolving series of link-based cyberattacks targeting Microsoft 365 environments, including Windows 365. These incidents encompass sophisticated phishing campaigns, exploitation of vulnerabilities in Office applications, and recent attacks leveraging compromised Wi-Fi networks to steal credentials and bypass multi-factor authentication, with new threats emerging as recently as August 2026.

Share:

Quick Answer

The 'Windows 365 Link Hacking Incident' is not a single event but a broad category of ongoing cyber threats primarily involving malicious links. Attackers frequently use phishing emails to direct users to fake Microsoft login pages or trick them into granting access via legitimate OAuth authorization flows, often bypassing multi-factor authentication (MFA) through techniques like device code phishing. Recent developments in 2026 include the emergence of Phishing-as-a-Service (PhaaS) platforms like Kali365 and sophisticated campaigns like 'CaptiveCrunch' by the Russian threat actor Midnight Blizzard, which compromises hospitality Wi-Fi networks to redirect users to phishing sites for Microsoft 365 credentials. Microsoft continues to issue patches and security guidance to combat these evolving threats.

📊Key Facts

Total Microsoft Vulnerabilities (2024)
1,360
BeyondTrust, Virtru
Critical Microsoft Vulnerabilities (2025)
157
BeyondTrust
Elevation of Privilege Vulnerabilities (2025)
40% of total (509)
BeyondTrust
Kali365 PhaaS Emergence
April 2026
FBI, IC3
Device Code Phishing Detections Surge (Early 2026)
37.5 times
BleepingComputer via Paubox

📅Complete Timeline12 events

1
2024Major

Record Number of Microsoft Vulnerabilities Reported

Microsoft reported a record 1,360 vulnerabilities across its products, including Windows, Office, Edge, and Azure, marking an 11% increase from the previous record.

2
July 19, 2025Major

Microsoft SharePoint Zero-Day Exploit

Hackers exploited a zero-day vulnerability in Microsoft SharePoint, impacting businesses and government agencies globally, prompting emergency patches from Microsoft.

3
August 12, 2025Major

Critical Microsoft Office RCE Vulnerabilities Patched

Microsoft issued urgent security updates for three serious Remote Code Execution (RCE) vulnerabilities (CVE-2025-53731, CVE-2025-53740, CVE-2025-53730) in its Office suite, which could be triggered by merely previewing a malicious document.

4
Second Half 2025Notable

Windows 365 Cloud PC Security Defaults Tightened

Microsoft began rolling out new security defaults for Windows 365 Cloud PCs, disabling clipboard, drive, USB, and printer redirections by default to reduce data exfiltration risks.

5
January 26, 2026Major

Emergency Patch for Microsoft Office/365 OLE Bypass (CVE-2026-21509)

Microsoft disclosed and patched CVE-2026-21509, a flaw affecting Microsoft 365 Apps for Enterprise and Office versions, allowing attackers to bypass OLE mitigations via malicious documents in phishing attacks.

6
February 2026Major

AI-Augmented Operations by Storm-2945 Begin

Microsoft observed the Russian threat actor Storm-2945 (Midnight Blizzard) conducting AI-augmented device code and OAuth code phishing campaigns, leading to Microsoft Entra device registration and data collection.

7
April 2026Critical

Kali365 Phishing-as-a-Service (PhaaS) Emerges

The FBI warned about Kali365, a new PhaaS platform distributed via Telegram, enabling attackers to steal OAuth tokens and bypass MFA in Microsoft 365 environments using AI-generated phishing lures and device code phishing.

8
May 2026Major

CaptiveCrunch Campaign Becomes Active

Microsoft identified the 'CaptiveCrunch' campaign, attributed to Midnight Blizzard (Storm-2945), actively targeting hospitality Wi-Fi networks to redirect users to phishing pages and steal Microsoft 365 accounts.

9
May 28, 2026Major

FBI Warns of Kali365 Targeting Microsoft 365

TechRadar reported on the FBI's warning regarding the Kali365 PhaaS service, highlighting its ability to gain persistent access to Microsoft 365 environments by stealing OAuth tokens through AI-generated phishing.

10
June 13, 2026Critical

FBI Public Service Announcement on Kali365 and Device Code Phishing

The FBI issued a PSA detailing how Kali365 abuses Microsoft's device code login portal to capture session tokens and bypass MFA, warning that device code phishing detections surged 37.5 times in early 2026.

11
July 30, 2026Major

Attackers Using Microsoft's Legitimate Login System for Phishing

Check Point researchers warned that attackers are increasingly using genuine login.microsoftonline.com OAuth authorization pages to camouflage phishing attacks, redirecting users to attacker-controlled endpoints after sign-in to steal authorization tokens.

12
August 4, 2026Critical

Microsoft Links CaptiveCrunch to Midnight Blizzard, Identifies New Malware

Microsoft officially linked the global CaptiveCrunch campaign, targeting hospitality Wi-Fi networks to steal Microsoft 365 accounts, to the Russian threat actor Midnight Blizzard (APT29) and identified new malware families, CornFlake and ChocoShell.

🔍Deep Dive Analysis

The landscape of 'link hacking' targeting Microsoft 365, which includes Windows 365, has evolved significantly, moving beyond simple malicious links to highly sophisticated, multi-stage attacks. These incidents are not confined to a single breach but represent a continuous cat-and-mouse game between attackers and Microsoft's security measures.

Initially, many link-based attacks focused on traditional phishing, where users were lured by malicious emails to fake login pages designed to steal credentials. However, as security measures like multi-factor authentication (MFA) became more widespread, attackers adapted. A significant turning point has been the rise of 'device code phishing' and OAuth token theft. This technique, which became increasingly prevalent in 2026, involves attackers initiating a legitimate Microsoft device code authorization flow and then tricking users into entering the generated code on a genuine Microsoft verification page. Unbeknownst to the user, this action grants the attacker's device access to their Microsoft 365 account, often bypassing MFA entirely. Phishing-as-a-Service (PhaaS) platforms, such as Kali365, which emerged in April 2026, have democratized these advanced techniques, making them accessible to less-skilled attackers through AI-generated lures and automated campaign tools.

Beyond phishing, vulnerabilities within Microsoft Office and 365 applications themselves have also been exploited through malicious links or documents. For instance, in January 2026, Microsoft disclosed CVE-2026-21509, a flaw affecting Microsoft 365 Apps for Enterprise and various Office versions, which allowed attackers to bypass Object Linking and Embedding (OLE) mitigations. This vulnerability could be exploited by tricking users into opening malicious documents, leading to local security feature bypasses. In August 2025, Microsoft also addressed critical Remote Code Execution (RCE) vulnerabilities (CVE-2025-53731, CVE-2025-53740) in its Office suite that could be triggered merely by previewing a malicious document.

The most recent and notable development, as of July-August 2026, is the 'CaptiveCrunch' campaign, attributed to the Russian state-sponsored threat actor Midnight Blizzard (also known as APT29). This sophisticated operation targets hospitality Wi-Fi networks, manipulating DNS settings on captive portal equipment to redirect users to phishing pages impersonating Microsoft 365 login portals. The campaign, which has been active since at least early May 2026 and has shown signs of AI-augmented operations since February 2026, aims to steal Microsoft 365 credentials and authentication tokens. Microsoft has identified new malware families, CornFlake and ChocoShell, associated with this campaign, capable of persistent access and data exfiltration.

The consequences of these link-based attacks are severe, ranging from credential theft and unauthorized access to email, files, and Teams chats, to broader data exfiltration and business email compromise. Microsoft has responded by issuing emergency patches, tightening security defaults (e.g., for Windows 365 Cloud PCs in late 2025), and providing extensive guidance on preventing phishing and securing accounts. However, the sheer volume of vulnerabilities (over 1,200 reported in 2024, with 157 critical ones in 2025) and the continuous innovation by threat actors mean that securing Microsoft 365 environments remains an ongoing challenge, requiring vigilance and robust security practices from users and organizations alike.

What If...?

Explore alternate histories. What if Microsoft 365 Link-Based Hacking Incidents and Phishing Campaigns made different choices?

Explore Scenarios
Building relationship map...

People Also Ask

What is the 'Windows 365 Link Hacking Incident'?
The 'Windows 365 Link Hacking Incident' refers to a series of sophisticated and ongoing cyberattacks that leverage malicious links to compromise Microsoft 365 accounts, including those used with Windows 365. These incidents involve various techniques like phishing, exploiting software vulnerabilities, and manipulating network infrastructure.
How do attackers use links to hack Microsoft 365 accounts?
Attackers use links in several ways: directing users to fake login pages to steal credentials, tricking users into granting malicious applications access via legitimate OAuth authorization flows (device code phishing), or exploiting vulnerabilities in Office documents that are triggered by opening or even previewing a malicious file.
What is device code phishing and why is it effective?
Device code phishing is a technique where attackers initiate a legitimate Microsoft device login process to obtain a short code, then trick users into entering this code on a real Microsoft verification page. This action unknowingly authorizes the attacker's device to access the user's Microsoft 365 account, often bypassing multi-factor authentication (MFA). It's effective because it leverages Microsoft's legitimate infrastructure.
Who is behind the recent 'CaptiveCrunch' attacks?
The 'CaptiveCrunch' campaign, which targets hospitality Wi-Fi networks to steal Microsoft 365 credentials, has been attributed by Microsoft to Midnight Blizzard, also known as APT29 or Storm-2945, a Russian state-sponsored threat actor.
What measures can users take to protect against these link-based attacks?
Users should enable and properly configure multi-factor authentication (MFA), be vigilant about suspicious emails and links (hovering before clicking), verify sender details, and be cautious about granting permissions to applications. Organizations should implement conditional access policies, regularly update software, and monitor for unusual activity.