Jalisco Phishing Targets Microsoft 365 MFA

Toolkit Targets Microsoft 365 Accounts

Cybersecurity researchers have identified Jalisco, a new phishing toolkit that targets Microsoft 365 accounts protected by multifactor authentication (MFA).

Jalisco uses device-code phishing to convince victims to authorize an attacker’s session. The victim enters an attacker-provided code into Microsoft’s legitimate sign-in page and completes MFA normally. This gives the attacker valid OAuth tokens without needing to steal the victim’s password.

Why It Matters

Once inside an account, an attacker may be able to access email, OneDrive, SharePoint and other connected cloud services. Attackers may also register their own devices, potentially maintaining access even after the victim changes their password.

Jalisco does not exploit a Microsoft vulnerability or technically break MFA. It uses social engineering to trick the victim into approving access.

How Businesses Can Respond

  • Block device-code authentication unless it is required.
  • Monitor Microsoft Entra ID for unusual sign-ins and devices.
  • Remove unauthorized devices and revoke compromised sessions.
  • Teach employees never to enter a device code they did not request.
  • Verify unexpected document, PDF or meeting invitations separately.

MFA remains essential, but it cannot protect users who are tricked into authorizing an attacker directly. Strong identity controls, monitoring and employee awareness are also necessary.