IntelSecurity IncidentPL
HIGHSecurity Incident·priority

Phishing-as-a-Service and AI-driven cybercrime surge—are Microsoft 365 and retail networks next?

Intelrift Intelligence Desk·Tuesday, August 4, 2026 at 10:03 PMEurope4 articles · 4 sourcesLIVE

A new wave of cybercrime is being enabled by “phishing-as-a-service” platforms that are evolving beyond simple credential theft. Greatness, a PhaaS provider, has expanded from credential phishing into adversary-in-the-middle and device-code phishing specifically aimed at Microsoft 365 accounts, increasing the likelihood of successful account takeovers and persistent access. In parallel, a study highlighted that artificial intelligence is fueling more than half of cybercrime in Africa, allowing criminals to launch faster, more sophisticated attacks while financial losses continue to mount. Separately, Poland’s Żabka convenience store chain reported that intruders accessed its environment through a third-party account, with the company confirming an intrusion that began in late July and involved access to Jira and other sensitive data. Geopolitically, these incidents point to a widening threat surface that crosses regions and sectors, turning everyday digital services into strategic infrastructure. Microsoft 365 targeting matters because it is a common identity and collaboration layer for governments, contractors, and large enterprises, meaning compromise can translate into intelligence collection, operational disruption, and supply-chain leverage. The Africa-focused AI-driven cybercrime finding suggests criminal ecosystems are becoming more industrialized, which can strain local financial systems and increase the probability of cross-border monetization schemes. The Żabka breach underscores how retail and logistics—often assumed to be “low priority”—can become stepping stones via third-party access, creating downstream risk for payments, inventory systems, and consumer data. Overall, the balance of power shifts toward attackers who can scale tooling, while defenders face higher costs in detection, incident response, and identity hardening. Market and economic implications are likely to concentrate in cybersecurity spending, identity and access management (IAM) demand, and insurance pricing for cyber risk. Enterprises using Microsoft 365 may see elevated risk premia for managed security services and endpoint protection, while device-code phishing and AitM techniques can increase the probability of business interruption events that hit revenue continuity. For Poland’s retail sector, a breach involving Jira and sensitive data can raise compliance and remediation costs and potentially affect consumer trust, with knock-on effects for IT vendors and payment processors. In Africa, AI-enabled cybercrime correlates with higher fraud losses and could pressure fintech underwriting, card-not-present fraud controls, and bank operational risk metrics. While the articles do not provide direct commodity or FX figures, the direction is clear: cyber incidents tend to lift demand for security tooling and can widen spreads in cyber-insurance and risk-managed corporate debt. The next watchpoints are technical and operational: whether Microsoft 365 tenants show spikes in device-code phishing attempts, whether Greatness-style PhaaS operators are observed reusing infrastructure, and whether defenders can detect AitM patterns early. For organizations, triggers include anomalous sign-ins, unusual OAuth consent flows, and evidence of third-party account compromise leading to internal tooling access like Jira. Regulators and boards should monitor incident reporting timelines, third-party risk assessments, and whether affected firms accelerate MFA enforcement, conditional access policies, and session controls. In the near term, expect more public disclosures as attackers monetize access, and more targeted guidance from security vendors on device-code and OAuth abuse. Escalation would be indicated by broader compromise of identity providers or coordinated campaigns against large Microsoft 365 user bases, while de-escalation would show up as successful takedowns, improved detection rates, and fewer follow-on intrusions after initial access.

Geopolitical Implications

  • 01

    Identity and collaboration platforms are becoming strategic targets for cross-sector disruption.

  • 02

    AI-driven criminal tooling increases the scale and speed of attacks, raising cross-border monetization risk.

  • 03

    Third-party access chains create systemic vulnerabilities in economic sectors beyond traditional finance.

Key Signals

  • Rising device-code phishing attempts and OAuth consent anomalies in Microsoft 365 telemetry.
  • Reuse of infrastructure by PhaaS operators and clustering of similar TTPs.
  • More third-party-driven intrusions reaching internal collaboration tools like Jira.

Topics & Keywords

phishing-as-a-serviceMicrosoft 365 account compromisedevice-code phishingadversary-in-the-middle attacksAI-enabled cybercrimethird-party account breachJira intrusionGreatness PhaaSdevice-code phishingMicrosoft 365 accountsadversary-in-the-middleAI cybercrime AfricaŻabkaJira breachthird-party account

Market Impact Analysis

Premium Intelligence

Create a free account to unlock detailed analysis

AI Threat Assessment

Premium Intelligence

Create a free account to unlock detailed analysis

Event Timeline

Premium Intelligence

Create a free account to unlock detailed analysis

Related Intelligence

Full Access

Unlock Full Intelligence Access

Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.