Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page
ID: 002cc2c5-ab0d-56b0-b7ea-6ad98b4c1d58
STIX ID: report--002cc2c5-ab0d-56b0-b7ea-6ad98b4c1d58
Feed Name: cybersecurityNews.com
Researchers reported an active phishing campaign that hijacks Microsoft’s Device Code Flow: victims open a malicious PDF or link that displays a one-time device code which, when copied and pasted into the genuine Microsoft authentication page, results in attackers receiving OAuth access tokens and full access to email, OneDrive, and Teams. The campaign ran in multiple regions (April–mid May 2026) and used region-specific lures; recommended mitigations include disabling unused Device Code Flow via Conditional Access, monitoring DeviceCodeSignIn events, enforcing device compliance, and improving email/link hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
