Cyber | July 7, 2025 | 4 min read | By Martin Patterson

Scary new trick hackers use to bypass security

Cyber criminals are always finding new ways to break through business defences. The latest threat, known as device code phishing, is one of the most alarming so far. It is catching many companies by surprise because attackers do not even need your password. Instead, they can still access your Microsoft account and bypass multi-factor authentication.

Scary new trick hackers use to bypass security

Cyber criminals are always finding new ways to break through business defences. The latest threat, known as device code phishing, is one of the most alarming so far. It is catching many companies by surprise because attackers do not even need your password. Instead, they can still access your Microsoft account and bypass multi-factor authentication.

What is device code phishing?

Device code phishing is a growing cyber security threat that targets people through real Microsoft login pages. Unlike normal phishing, which uses fake websites to steal passwords, this attack tricks you into giving access yourself.

It usually starts with a convincing email. The message might look like it’s from your HR team or a colleague. Often, it invites you to join a Microsoft Teams meeting and includes a link. The page you land on looks genuine because it is hosted on Microsoft’s own platform. You may even be asked to enter a short “device code” that appears in the email.

How this scam works

Here’s where things go wrong. When you enter that code, you are not logging yourself in. You are logging the attacker in on their device.

Because the process happens on a legitimate Microsoft page, it looks completely normal. There are no fake links or misspelled web addresses to alert you. Even worse, the attack can bypass multi-factor authentication. Since the login request is genuine, security tools often see nothing unusual.

Once inside your account, hackers can read emails, open files, and contact colleagues while pretending to be you. They can also capture your session token – a kind of digital pass that keeps you logged in. Therefore, even if you change your password, they might still have access for a while.

Why traditional security tools struggle

This scam is so effective because it looks real at every step. The victim sees a trusted Microsoft page, and the login is processed through genuine systems. As a result, most standard security tools do not detect the problem.

Moreover, attackers can remain hidden by using the captured session token. They can continue accessing company data without having to log in again. This makes the attack especially dangerous for businesses that rely heavily on Microsoft 365 for daily operations.

How to protect your business from device code phishing

The best protection is awareness. Train your team to pause before entering any code or logging in from an unexpected message. If someone sends you a code to use, ask yourself: did I request this? Do I know it’s real?

If you are unsure, verify the message through another trusted method, such as a direct phone call or your internal chat system. Never rely only on the email itself. Remember, Microsoft will never ask you to enter a code that someone else provides.

From a technical point of view, your IT department or managed service provider can also help.
They should:

  • Turn off device code authentication if your business does not need it.
  • Create rules that allow logins only from trusted devices and safe locations.
  • Regularly review and remove old or suspicious session tokens.
  • Provide ongoing staff training to keep everyone alert to new types of attack.

Staying ahead of evolving cyber threats

Cyber threats such as device code phishing show how quickly online scams evolve. Therefore, your security strategy must evolve too. By combining smart technology with regular staff awareness, your business will be much harder to trick.

Get in touch with our team to find out how we can improve your cyber security setup and protect your company from attacks like device code phishing. Together, we can keep your business safe and secure.

For more guidance on how to protect your organisation, visit the National Cyber Security Centre’s advice for businesses.”

Martin Patterson

By Martin Patterson

Technical Director

Martin is Technical Director at Qss IT, leading the technical strategy, cyber security initiatives, and infrastructure services provided to clients across the UK. He specialises in cloud technologies, Microsoft 365, cyber security, networking, and business resilience, helping organisations build secure, scalable, and future ready IT environments. Areas of expertise: Cyber Security, Cloud Infrastructure, Microsoft 365, Networking, Business Resilience