Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Bernie Sanders’ billionaire tax would soak about 900 people to fund ,000 checks for the middle class

Bernie Sanders’ billionaire tax would soak about 900 people to fund $3,000 checks for the middle class

4 March 2026
Harvard professor calls out ‘lie’ of needing 8 hours of sleep a night, says it’s Industrial Era ‘nonsense’

Harvard professor calls out ‘lie’ of needing 8 hours of sleep a night, says it’s Industrial Era ‘nonsense’

4 March 2026
How to choose the right mattress size

How to choose the right mattress size

4 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New Microsoft 2FA Bypass Attack Warning—Dangerous And Sneaky, Act Now
Innovation

New Microsoft 2FA Bypass Attack Warning—Dangerous And Sneaky, Act Now

Press RoomBy Press Room19 January 20254 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New Microsoft 2FA Bypass Attack Warning—Dangerous And Sneaky, Act Now

Update, Jan. 19, 2025: This story, originally published Jan. 18, now includes additional mitigation advice from cybersecurity experts regarding the latest Microsoft Sneaky 2FA bypass attack.

There is no escaping the phishing threat, as WhatsApp and PayPal users have been warned. Gmail and Outlook users don’t escape the attack warnings, and the addition of two-factor authentication bypass hacks just muddies the security waters. Now, French security researchers have exposed another new adversary-in-the-middle attack that targets Microsoft 365 accounts, stealing credentials and bypassing 2FA protections in the process. Here’s what you need to know.

The Sneaky 2FA Attack Warning

A cybercrime group known as Sneaky Log has been selling a 2FA-bypassing phishing-as-a-service kit called Sneaky 2FA since late last year. Researchers from the French cybersecurity company Sekoia have now published a new report warning how the kit, operating by way of a bot service via Telegram, targets Microsoft 365 account holders.

“Customers reportedly receive access to a licensed obfuscated version of the source code and deploy it independently,” Sekoia researchers Quentin Bourgue and Grégoire Clermont said, “Currently, Sneaky 2FA’s phishing pages are hosted on compromised infrastructure, frequently involving WordPress websites and other domains controlled by the attacker.” Costing $200 per month, the Sneaky Log sales team offers reductions that bring the cost down depending upon the length of the subscription.

Like so many of these kits, take a look at Rockstar 2FA, example, Sneaky 2FA harvests Microsoft 365 session cookies in order to bypass the 2FA process during subsequent attacks so that authentication appears, indeed is, legitimate as far as the session is concerned.

Elad Luz, head of research at Oasis Security, said that the threat actors had “blurred out screenshots of Microsoft webpages to create a convincing login background,” which made it “appear as though users will access legitimate content after successfully logging in.”

Meanwhile, Stephen Kowski, field chief technology officer at SlashNext Email Security+, said “this kit’s sneaky aspects include its sophisticated ability to populate victim email addresses automatically, its evasion of detection through Cloudflare Turnstile challenges, and its clever redirection of security tools to Wikipedia pages” adding that it is “particularly dangerous for Microsoft 365 environments.”

I have reached out to Microsoft for a statement.

Mitigating 2FA Bypass Attacks

Intercepting both credentials and 2FA codes in real time means that attackers are able to bypass what Patrick Tiquet, vice President of security and architecture at Keeper Security, calls “one of the most relied-upon layers of account protection.” The sneakiness, Tiquet warned, and its sophistication lies in its anti-analysis features such as traffic filtering and checks to avoid detection. As well as “convincing pre-populated login forms, which enhance its success rate,” not to mention that hosting the phishing pages on compromised infrastructure adds another layer of deception, according to Tiquet. Luckily, there are mitigations that organizations can consider, and the first, Tiquet said, is “implementing Privileged Access Management to restrict access and contain potential damage from compromised accounts.” By pairing this with robust password management, Tiquet continued, you can ensure that credentials are strong, unique and securely stored, reducing exposure to phishing campaigns. “Additionally, a password manager will prevent users from entering credentials into spoofed websites because the tool will only auto-fill credentials on the authentic webpage,” Tiquet concluded.

Although this 2FA bypass attack targets Microsoft 365 users, this kind of threat is not just aimed at Microsoft and can impact users of any accounts that are perceived to be of high value to the threat actors involved. The common factor, as alluded to already, in most such attacks is the phishing aspect, so that’s where the mitigation methodology must sit: this fascinating article explores methods of mitigating phishing attacks.

2FA Bypass 2FA hack Hack two-factor authentication Hacking 2FA Microsoft Microsoft 2FA hack Microsoft 365 Sekoia Sneaky 2FA two-factor authentication bypass
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Want to live forever? Meta patented an AI model that would keep your profile active after you die

Want to live forever? Meta patented an AI model that would keep your profile active after you die

3 March 2026

When Claude Paused: An AI Doomsday Preview And The Question Of Human Survival

3 March 2026

Data Plateau: Hit The Scaling Wall With AI Or Remain An Innovator?

3 March 2026
New Leak Signals Unprecedented Design Change

New Leak Signals Unprecedented Design Change

1 March 2026
Is Tourism A Tool Or A Threat?

Is Tourism A Tool Or A Threat?

1 March 2026
Trust In The AI Age

Trust In The AI Age

1 March 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

6 February 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Qualcomm CEO: “Resistance is futile” as 6G mobile revolution approaches  

Qualcomm CEO: “Resistance is futile” as 6G mobile revolution approaches  

4 March 20261 Views
 billion of the insurance industry is at risk from AI, BofA says

$15 billion of the insurance industry is at risk from AI, BofA says

4 March 20261 Views
Cities join Amazon in ending contracts with license scanner Ring after that Super Bowl ad

Cities join Amazon in ending contracts with license scanner Ring after that Super Bowl ad

4 March 20261 Views
U.S. oil and gas exporters benefit from the Iran war, but can’t fill the supply gap as prices spike

U.S. oil and gas exporters benefit from the Iran war, but can’t fill the supply gap as prices spike

4 March 20261 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Bernie Sanders’ billionaire tax would soak about 900 people to fund ,000 checks for the middle class

Bernie Sanders’ billionaire tax would soak about 900 people to fund $3,000 checks for the middle class

4 March 2026
Harvard professor calls out ‘lie’ of needing 8 hours of sleep a night, says it’s Industrial Era ‘nonsense’

Harvard professor calls out ‘lie’ of needing 8 hours of sleep a night, says it’s Industrial Era ‘nonsense’

4 March 2026
How to choose the right mattress size

How to choose the right mattress size

4 March 2026
Most Popular
How Firm Should Your Bed Be?

How Firm Should Your Bed Be?

4 March 20261 Views
Qualcomm CEO: “Resistance is futile” as 6G mobile revolution approaches  

Qualcomm CEO: “Resistance is futile” as 6G mobile revolution approaches  

4 March 20261 Views
 billion of the insurance industry is at risk from AI, BofA says

$15 billion of the insurance industry is at risk from AI, BofA says

4 March 20261 Views
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.