Microsoft has disclosed a large-scale credential theft campaign that used code of conduct-themed emails and legitimate email services to direct users to attacker-controlled domains for stealing authentication tokens. The campaign, observed between April 14 and 16, 2026, targeted more than 35,000 users from over 13,000 organizations across 26 countries.
