The New Phishing Click: How OAuth Consent Bypasses MFA
In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens without triggering MFA, leveraging the instinctive nature of consent clicks and the lack of visibility into the consent layer by security controls. This represents a shift in phishing tactics, moving beyond simple credential theft to exploiting the granular permissions granted through OAuth, creating 'toxic combinations' that significantly expand the attack surface.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
