• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

The Best Security Consultants

Menu
  • Industries
      • Aviation and Airport Security Consultants Australia
      • Defence Industry Security Consulting
      • Government Security Consulting
      • Healthcare & Hospitals Security Consulting
      • Corrections and Detention
      • Maritime Security Consultant
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • School and Education Security Consultant
      • Telecommunications Security Consultant
      • Utilities
      • Places of Faith and Worship
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity Consultants
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Cyber Audits
      • Data
      • Pandemic Planning
      • Azure
      • Electronic Security
      • IT Disaster Recovery Planning
      • Business Continuity Consultants
      • Identity Theft Consultant​
      • Security Consultants
      • Security Camera and CCTV Consultant
      • ISO
      • Duress Alarms
      • Cloud
      • AWS
      • Awareness Training
      • Penetration Testing
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Locations
    • Security Consultant Melbourne
    • Security Consultant Sydney
    • Security Consultant Brisbane
    • Security Consultant Adelaide
    • Security Consultant Canberra
    • Security Consultant Perth
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

Phishing Scam Targeting Microsoft

You are here: Home / Security News / Phishing Scam Targeting Microsoft

Microsoft has issued warnings about a new phishing scam, which aims to trick users into giving out OAuth permissions to an app, then allowing attackers to read and access their emails. An OAuth permission gives Internet users the option to grant websites and applications access to their information on different websites, without giving away their passwords. This then allows them to gain access to emails, calendars and contacts. The scam was first detected by a phishing hunter, who then posted his findings on Twitter. “Massive active image-based #phishing campaign missed by Defender for @Office365 for several days,” read the tweet, which then prompted Microsoft to investigate.

Protect Your Privacy

Microsoft has advised that the phishing scam was successful mainly against targets that were not using multi-factor authentication (MFA). Therefore, in order to protect your privacy and security, you should consider the following:

  • Keep your software up to date. Hackers target security flaws in software, so always keep your software updated to cover holes in security.
  • Implement a strong password. By enforcing a strong password, you can prevent unauthorized access against brute force attacks and breaches. Also think about certain requirements for your passwords using upper case and lower case letters, symbols and numbers, and ensuring all password are at least 8 characters long.
  • Use Multi-Factor Authentication (MFA). MFA requires a user to provide two or more verification factors to gain access to their account. One of the most common types of MFA is a one-time password (OTP). An OTP is a code that is sent either via SMS, email or to a mobile app. The code is typically between four and eight digits long.

To find out how best to protect your organisation and enhance cybersecurity, contact us at Agilient.

Author: Mahdi Kobeissi, Cybersecurity Consultant

Tweet
Share

Security News

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2025 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692

Our Services

Security Consultant

Security Consultant Sydney

Security Consultant Melbourne

Security Consultant Canberra
Security Consultant Perth

Security Consultant Adelaide

Security Consultant Brisbane