logo

Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page

ID: 002cc2c5-ab0d-56b0-b7ea-6ad98b4c1d58

STIX ID: report--002cc2c5-ab0d-56b0-b7ea-6ad98b4c1d58

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: Tushar Subhra Dutta

...
...

Researchers reported an active phishing campaign that hijacks Microsoft’s Device Code Flow: victims open a malicious PDF or link that displays a one-time device code which, when copied and pasted into the genuine Microsoft authentication page, results in attackers receiving OAuth access tokens and full access to email, OneDrive, and Teams. The campaign ran in multiple regions (April–mid May 2026) and used region-specific lures; recommended mitigations include disabling unused Device Code Flow via Conditional Access, monitoring DeviceCodeSignIn events, enforcing device compliance, and improving email/link hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.