September 2026 phishing hit US Microsoft 365 and payments
ANY.RUN reports CSuite, N0va, and IronToll stole Microsoft 365 sessions, tokens, and payment data, largely from US targets.
ANY.RUN's September 2026 roundup describes phishing against US and European organizations by campaigns named CSuite, N0va, and IronToll. CSuite combined Microsoft 365 session theft with legitimate remote-management tools including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect, using brand lures such as Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365; the roundup also listed Dropbox. N0va used device-code phishing to capture Microsoft 365 access and refresh tokens, while Cyber Security News cited ANY.RUN H1 2026 figures that OAuth device-code phishing rose 483.7% and cloud infrastructure abuse rose 90.7%. IronToll was linked to 114 domains in more than 12 countries and stole card data and one-time passwords through cloned payment pages and a live operator panel. The sources give different US shares for CSuite: 51% of 351 sandbox submissions versus 60% of identified victim organizations.
- CSuite combined Microsoft 365 session theft with legitimate remote-management tools including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.
- ANY.RUN said 51% of 351 CSuite-linked sandbox submissions came from the United States; Cyber Security News said US organizations were 60% of identified CSuite victims.
- N0va used OAuth device-code phishing to steal Microsoft 365 access and refresh tokens through legitimate authentication flows.
- ANY.RUN's H1 2026 figures, cited by Cyber Security News, put the rise in OAuth device-code phishing at 483.7% and cloud infrastructure abuse at 90.7%.
- IronToll was tied to 114 domains across more than 12 countries and used cloned payment pages and a live operator panel to steal card data and one-time passwords.
- Lures impersonated Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365; the ANY.RUN roundup also named Dropbox.
Coverage timelineoldest first · each row is one article
- · 2d agoMajor Cyber Attacks in September 2026: US Organizations Face Session Theft, Remote Access, and Payment Fraud
ANY.RUN· 70
September campaigns CSuite, N0va, and IronToll phished US organizations for Microsoft 365 sessions, tokens, and payment data.
- · 1d agoHow US SOCs and MSSPs Can Use Threat Intelligence to Detect Phishing Infrastructure Earlier
Cyber Security News· 46
ANY.RUN says OAuth device-code phishing jumped 483.7% in H1 2026.