Device Code Phishing in Microsoft 365: The Attack That Can Steal Your Session Without Your Password

Device code phishing is a clever Microsoft 365 attack that can steal an authenticated session without stealing your password.** An attacker starts a login, sends you the device code, and tricks you into completing the sign-in on Microsoft's genuine website. Even MFA may not save you because you're unknowingly approving the attacker's session. The best defence is simple: **if you didn't start the login, don't finish it.

Create a website or blog at WordPress.com

Up ↑