Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL
Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.
SMS phishing campaigns like 0ktapus harvest credentials and MFA codes through fake sign-in pages. Detection focuses on the sign-ins that follow.
Signals worth watching
- Successful sign-ins shortly after a user received suspicious SMS messages (often learned from user reports).
- Sign-ins from new IPs or devices that complete MFA with one-time codes, especially from hosting providers or VPN services.
- Multiple employees' accounts signing in from the same unfamiliar IP within a short time.
- New MFA methods registered right after a suspicious sign-in.
- Entra ID Protection detections for attacker-in-the-middle activity or anomalous tokens.
Where the data lives
- Entra ID sign-in logs and audit logs.
- Identity Protection risk detections.
- User reports to the security team (create an easy reporting channel for SMS phishing).
A starting query
Multiple users signing in from the same new IP:
SigninLogs
| where TimeGenerated > ago(1d) and ResultType == "0"
| summarize Users = dcount(UserPrincipalName), UserList = make_set(UserPrincipalName, 20)
by IPAddress, AutonomousSystemNumber
| where Users >= 3
Exclude known corporate egress IPs.
Response
- Revoke sessions and reset credentials for affected users.
- Remove any MFA methods registered by the attacker.
- Block the IP range and phishing domains.
- Notify staff about the active campaign.
- Accelerate FIDO2 or passkey rollout for targeted groups.
- 0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies Incident Teardowns
- How to Deploy FIDO2 Security Keys for High-Risk Users How-To & Hardening
- CIO Brief: The Case for Hardware Security Keys CIO Briefings