Forg365, a newly discovered Phishing-as-a-Service (PhaaS) platform, is actively targeting Microsoft 365 users by exploiting device code authentication and adversary-in-the-middle (AitM) session theft techniques. This campaign poses a significant threat to organisations relying on Microsoft 365 for email, file storage and productivity, as attackers can steal session tokens and bypass multi-factor authentication (MFA) protections.
Forg365 PhaaS: A New Threat to Microsoft 365 Users
The Forg365 PhaaS platform first emerged in June 2026, quickly gaining attention in the cybersecurity community due to its sophisticated use of Microsoft 365 authentication flows. Forg365 is sold on underground forums, enabling even less technically skilled threat actors to launch convincing phishing campaigns against business users.
The platform is designed specifically to target Microsoft 365 accounts. By abusing the device code authentication flow, Forg365 can obtain access tokens and session cookies, allowing attackers to access mailboxes, files and other sensitive data within an organisation’s cloud environment. Notably, this method enables attackers to bypass MFA, making it especially dangerous for companies that depend on basic MFA for security.
How Forg365 Exploits Device Code Authentication and AitM
Forg365 attacks start with a phishing email or lure, tricking victims into initiating a device authentication process. The attackers’ infrastructure mirrors legitimate Microsoft 365 login pages, making detection difficult for end users. Here is how the attack unfolds:
- Initial Phishing: The victim receives an email containing a link or QR code leading to a spoofed Microsoft 365 sign-in page.
- Device Code Flow Manipulation: The phishing website prompts the user to enter a device code, a legitimate process for accessing Microsoft 365 on new devices.
- Adversary-in-the-Middle (AitM) Attack: Forg365 intercepts the device code and communicates with Microsoft’s real authentication service, capturing the authentication flow.
- Session Token Theft: When the victim completes the authentication, Forg365 steals the resulting session cookies and tokens, granting the attacker persistent access.
- MFA Bypass: Since the authentication appears legitimate and uses the victim’s credentials, MFA challenges are satisfied, and attackers gain access without further prompts.
This process allows attackers to assume the victim’s identity within Microsoft 365, often without triggering security alerts. The session tokens can remain valid for hours or days, depending on the organisation’s security configuration.
Timeline and Exploitation Status
The first signs of Forg365 activity were observed in early June 2026, with security researchers identifying multiple phishing kits and templates linked to the platform on underground markets by mid-June. By late June, several organisations reported unauthorised Microsoft 365 logins traced back to Forg365 sessions.
Forg365’s rapid adoption stems from its ease of use, low cost and ability to automate large-scale campaigns targeting business users. Security researchers have confirmed that active campaigns are ongoing, with attackers specifically targeting sectors such as finance, legal and healthcare, where Microsoft 365 usage is widespread.
As of the beginning of July 2026, there is evidence that Forg365 is being updated to support additional evasion techniques, including dynamic phishing pages and countermeasures against automated security scanners. Microsoft has acknowledged the issue and is working on enhanced monitoring and detection rules, but no broad mitigation has yet been released for the underlying abuse of the device code flow.
Who Is Affected by Forg365?
The primary targets are organisations using Microsoft 365 for business productivity, email and cloud storage. Both small and large enterprises are at risk, with attackers focusing on users who have access to sensitive data or administrative privileges. Specifically, the following are affected:
- Microsoft 365 users, especially those with basic or conditional MFA enabled
- Organisations relying on device code authentication for remote or mobile access
- Sectors with high-value data, including finance, healthcare, legal and government
Products at risk include all Microsoft 365 web and cloud services that support device code authentication, such as Outlook, SharePoint, OneDrive and Teams.
Why Forg365 Matters Now
This campaign demonstrates how attackers are adapting to modern authentication methods. By abusing device code flows and leveraging AitM tactics, Forg365 sidesteps traditional security controls, including MFA. The immediate risk is unauthorised access to sensitive corporate data, leading to data breaches, business email compromise and potential regulatory consequences.
Immediate Steps for Organisations
While Microsoft is working on detection improvements, organisations should:
- Monitor for unusual Microsoft 365 logins and session activity
- Educate users on device code phishing and session theft risks
- Review authentication policies and limit device code usage where possible
- Consider advanced security solutions that can detect AitM phishing attempts
Rapid awareness and targeted monitoring are critical while a comprehensive vendor patch or mitigation is pending.
Originally reported by thehackernews.com.







