Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

21 May 2026
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New Microsoft 2FA Bypass Attack Warning—Dangerous And Sneaky, Act Now
Innovation

New Microsoft 2FA Bypass Attack Warning—Dangerous And Sneaky, Act Now

Press RoomBy Press Room19 January 20254 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New Microsoft 2FA Bypass Attack Warning—Dangerous And Sneaky, Act Now

Update, Jan. 19, 2025: This story, originally published Jan. 18, now includes additional mitigation advice from cybersecurity experts regarding the latest Microsoft Sneaky 2FA bypass attack.

There is no escaping the phishing threat, as WhatsApp and PayPal users have been warned. Gmail and Outlook users don’t escape the attack warnings, and the addition of two-factor authentication bypass hacks just muddies the security waters. Now, French security researchers have exposed another new adversary-in-the-middle attack that targets Microsoft 365 accounts, stealing credentials and bypassing 2FA protections in the process. Here’s what you need to know.

The Sneaky 2FA Attack Warning

A cybercrime group known as Sneaky Log has been selling a 2FA-bypassing phishing-as-a-service kit called Sneaky 2FA since late last year. Researchers from the French cybersecurity company Sekoia have now published a new report warning how the kit, operating by way of a bot service via Telegram, targets Microsoft 365 account holders.

“Customers reportedly receive access to a licensed obfuscated version of the source code and deploy it independently,” Sekoia researchers Quentin Bourgue and Grégoire Clermont said, “Currently, Sneaky 2FA’s phishing pages are hosted on compromised infrastructure, frequently involving WordPress websites and other domains controlled by the attacker.” Costing $200 per month, the Sneaky Log sales team offers reductions that bring the cost down depending upon the length of the subscription.

Like so many of these kits, take a look at Rockstar 2FA, example, Sneaky 2FA harvests Microsoft 365 session cookies in order to bypass the 2FA process during subsequent attacks so that authentication appears, indeed is, legitimate as far as the session is concerned.

Elad Luz, head of research at Oasis Security, said that the threat actors had “blurred out screenshots of Microsoft webpages to create a convincing login background,” which made it “appear as though users will access legitimate content after successfully logging in.”

Meanwhile, Stephen Kowski, field chief technology officer at SlashNext Email Security+, said “this kit’s sneaky aspects include its sophisticated ability to populate victim email addresses automatically, its evasion of detection through Cloudflare Turnstile challenges, and its clever redirection of security tools to Wikipedia pages” adding that it is “particularly dangerous for Microsoft 365 environments.”

I have reached out to Microsoft for a statement.

Mitigating 2FA Bypass Attacks

Intercepting both credentials and 2FA codes in real time means that attackers are able to bypass what Patrick Tiquet, vice President of security and architecture at Keeper Security, calls “one of the most relied-upon layers of account protection.” The sneakiness, Tiquet warned, and its sophistication lies in its anti-analysis features such as traffic filtering and checks to avoid detection. As well as “convincing pre-populated login forms, which enhance its success rate,” not to mention that hosting the phishing pages on compromised infrastructure adds another layer of deception, according to Tiquet. Luckily, there are mitigations that organizations can consider, and the first, Tiquet said, is “implementing Privileged Access Management to restrict access and contain potential damage from compromised accounts.” By pairing this with robust password management, Tiquet continued, you can ensure that credentials are strong, unique and securely stored, reducing exposure to phishing campaigns. “Additionally, a password manager will prevent users from entering credentials into spoofed websites because the tool will only auto-fill credentials on the authentic webpage,” Tiquet concluded.

Although this 2FA bypass attack targets Microsoft 365 users, this kind of threat is not just aimed at Microsoft and can impact users of any accounts that are perceived to be of high value to the threat actors involved. The common factor, as alluded to already, in most such attacks is the phishing aspect, so that’s where the mitigation methodology must sit: this fascinating article explores methods of mitigating phishing attacks.

2FA Bypass 2FA hack Hack two-factor authentication Hacking 2FA Microsoft Microsoft 2FA hack Microsoft 365 Sekoia Sneaky 2FA two-factor authentication bypass
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 2026
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 2026
2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

21 May 2026
​How AI Is Changing The Economics Of Integration

​How AI Is Changing The Economics Of Integration

21 May 2026
Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers

Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers

21 May 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 20261 Views
‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

21 May 20260 Views
2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

21 May 20262 Views
Wall Street thinks there’s a chance the S&P 500 could go 20% higher by 2027

Wall Street thinks there’s a chance the S&P 500 could go 20% higher by 2027

21 May 20262 Views

Recent Posts

  • Securing The Internet’s Humanity
  • Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’
  • Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do
  • MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy
  • Why Complexity Is The Insider Threat Hiding In Plain Sight

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

21 May 2026
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 2026
Most Popular
MacKenzie Scott snubbed from top donors list despite  billion philanthropy

MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

21 May 20262 Views
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 20261 Views
‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

21 May 20260 Views

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.