Mark RadarMARK RADAR
EN
Event File FINTECH Microsoft Phishing

Microsoft Warns Hackers Are Exploiting OAuth Redirects to Intercept Credentials in Man-in-the-Middle Attacks

1 reports · First detected 2026-03-04 · Last active 2026-03-04

OAuth is an authorization standard widely used by websites and cloud services. After users sign in, they are redirected to a preset URL, allowing third-party applications to obtain limited access. Microsoft’s security team said attackers are exploiting gaps in the process’s validation controls to lure victims to spoofed pages, posing a particular concern for governments and public-sector organizations that rely on centralized identity authentication.

The latest technique deliberately inserts invalid parameters into OAuth requests and exploits redirect logic to send users to malicious websites. Attackers then use the EvilProxy man-in-the-middle framework to intercept login credentials and session cookies, and may even distribute malware. Microsoft has not disclosed the number of affected organizations, the financial losses or the exact discovery date, but has warned relevant organizations to strengthen redirect URL validation and session protections.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR