A wave of phishing as a service (PhaaS) kits in 2026 — led by Forg365, Jalisco, and OmegaLord — bypasses multi factor authentication by hijacking the legitimate sign in process itself, not by breaking cryptography. The ForgCookie browser extension then refreshes stolen session cookies automatically, giving attackers...
Research answer

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What is the latest wave of phishing threats targeting Microsoft 365 accounts, including the Forg3. Article summary: Here is a comprehensive, sourced analysis of the latest wave of Microsoft 365 phishing threats as of July 2026.. Topic tags: general, government, general web, user generated, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it usefu
Security researchers have documented a sharp escalation in phishing-as-a-service (PhaaS) platforms and kits specifically engineered to bypass multi-factor authentication (MFA) on Microsoft 365 accounts. Rather than breaking cryptographic MFA flows, these attacks hijack the legitimate authentication process itself — intercepting session tokens, abusing OAuth device-code flows, or proxying real logins so the victim's own MFA approval works in the attacker's favor TCR.
First disclosed July 9, 2026 by ZeroBEC and BleepingComputer, Forg365 is a subscription-based ($400/month) PhaaS platform distributed via Telegram CC. It bundles three breakthrough capabilities:
microsoft.com/devicelogin, which authorizes the attacker's client) SC.A companion browser extension, ForgCookie, is compatible with Chrome, Edge, and Brave C. Once the victim's session tokens or cookies are harvested, ForgCookie automatically refreshes stolen session cookies, allowing the attacker to maintain access to Microsoft 365 services (Outlook, Teams, OneDrive, SharePoint) without re-authentication — even after the victim changes their password IC. This turns a one-time token grab into persistent, long-term compromise.
Disclosed by ReliaQuest and BleepingComputer on July 14, 2026, Jalisco is a device-code phishing kit actively used against Microsoft 365 accounts RS. It works by:
This means MFA is not "broken" — it is weaponized.
Also reported July 14, 2026, OmegaLord takes a different approach: it masquerades as a fake PDF reader browser page RS. When victims land on the page:
Multiple sources confirm a broader industry trend:
The critical insight across all these threats is that MFA is not technically defeated — it is co-opted:
| Technique | What Happens | Why MFA Doesn't Stop It |
|---|---|---|
| Device-code phishing | Victim enters attacker's code at Microsoft's real login page, completes their own MFA | The token goes to the attacker's app. MFA approved the right user — for the wrong client. |
| AiTM proxying | Victim logs in through attacker's proxy, MFA completes normally | Attacker captures the session cookie in real time and hijacks the session. |
| Credential + OTP harvesting | Fake login form captures password and OTP simultaneously | OTP is used immediately by the attacker before it expires. |
This is why traditional MFA alone is no longer sufficient defense TWS.
Based on multiple advisories, the following mitigations are strongly recommended:
devicecode authentication).offline_access, Mail.Read, or Files.ReadWrite.All permissions.These recommendations are drawn from the FBI PSA I, Microsoft Security Blog M, BleepingComputer RC, and ReliaQuest threat analysis S.
The 2026 wave of Microsoft 365 phishing — led by Forg365 (with its ForgCookie persistence extension), Jalisco, OmegaLord, and the broader ecosystem of device-code and AiTM kits — represents a paradigm shift. Attackers no longer need to steal passwords or break MFA. Instead, they abuse the OAuth trust model to make the victim's own authentication authorize an attacker-controlled session. The security community's consensus recommendation is a zero-trust posture: disable unused auth flows, enforce Conditional Access, monitor token grants, and move toward phishing-resistant MFA ICSC.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
A wave of phishing as a service (PhaaS) kits in 2026 — led by Forg365, Jalisco, and OmegaLord — bypasses multi factor authentication by hijacking the legitimate sign in process itself, not by breaking cryptography.
A wave of phishing as a service (PhaaS) kits in 2026 — led by Forg365, Jalisco, and OmegaLord — bypasses multi factor authentication by hijacking the legitimate sign in process itself, not by breaking cryptography. The ForgCookie browser extension then refreshes stolen session cookies automatically, giving attackers persistent access to Outlook, Teams, and OneDrive even after a password change.