Overview
A phishing toolkit known as N0va is targeting organisations across North America and Europe using an increasingly important attack technique: abusing legitimate authentication processes rather than relying solely on obvious fake login pages or malware. The campaign impersonates familiar business services including Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom and Adobe Sign. Once a user is drawn into the authentication process, attackers can potentially capture access and refresh tokens and establish access to corporate resources through the compromised identity. For CIOs, IT managers and security leaders, this reinforces a fundamental shift in cybersecurity: identity has become one of the most important enterprise security boundaries.
Why This Phishing Is Harder to Spot
Traditional phishing awareness often teaches users to identify suspicious login pages, unusual domains or unexpected password requests. N0va makes this more difficult by combining trusted brands with legitimate authentication flows. The reported attack chain can involve device-code phishing, legitimate authentication, token capture and subsequent token exchange or device registration. This means a user may interact with a real authentication service while unknowingly authorising access that benefits the attacker. The attack therefore targets trust in the authentication process itself, not simply the user’s password.
A Compromised Identity Can Open Multiple Doors
Modern organisations increasingly rely on single sign-on to simplify access across email, collaboration platforms, documents and cloud applications. This improves productivity, but it also increases the value of a compromised identity. Once an attacker obtains valid session or authentication tokens, the impact can extend beyond one application. Depending on the user’s permissions, access could expose email, corporate files, sensitive information and additional connected cloud services. This is why identity incidents should not be treated as isolated phishing events. One compromised account can become the starting point for a much wider cloud compromise.
What IT Leaders Should Consider
Organisations need to move beyond relying on passwords and traditional MFA as their primary defence. Phishing-resistant authentication such as FIDO2 security keys and passkeys, strong Conditional Access policies and tighter device-registration controls can reduce opportunities for authentication abuse. Device-code authentication should also be reviewed and restricted where it is not genuinely required. Security teams should monitor unusual token activity, new device registrations, suspicious sign-ins and unexpected access to cloud resources. When an identity is suspected of compromise, simply resetting the password may not be enough — active sessions and tokens may also need to be revoked.
Identity Security Is Business Security
A compromised business account can quickly create financial, operational and reputational consequences. Attackers may gain access to confidential communication, customer information, intellectual property or payment processes while appearing to operate as a legitimate employee. This makes identity security more than an IT administration function. Leadership should understand how privileged identities are protected, how abnormal authentication behaviour is detected and how quickly compromised sessions can be contained.
Expert in the Cloud Insight
N0va demonstrates why organisations need to rethink the familiar advice that “MFA will protect the account.” MFA remains essential, but attackers are increasingly targeting the authentication session, tokens and workflows around it rather than attacking only the password. For CIOs and IT managers, the important question is therefore no longer simply: “Do our users have MFA enabled?” It should also be: “Can an attacker reuse or manipulate the trust created after authentication?” As organisations become more dependent on cloud services and single sign-on, protecting identity must include the entire authentication lifecycle — from the user and device to the token and session. In a cloud-first organisation, protecting identity increasingly means protecting the business itself.
Leave a Reply