Scary new trick hackers use to bypass security
Cyber criminals are always finding new ways to break through business defences. The latest threat, known as device code phishing, is one of the most alarming so far. It is catching many companies by surprise because attackers do not even need your password. Instead, they can still access your Microsoft account and bypass multi-factor authentication.
What is device code phishing?
Device code phishing is a growing cyber security threat that targets people through real Microsoft login pages. Unlike normal phishing, which uses fake websites to steal passwords, this attack tricks you into giving access yourself.
It usually starts with a convincing email. The message might look like it’s from your HR team or a colleague. Often, it invites you to join a Microsoft Teams meeting and includes a link. The page you land on looks genuine because it is hosted on Microsoft’s own platform. You may even be asked to enter a short “device code” that appears in the email.
How this scam works
Here’s where things go wrong. When you enter that code, you are not logging yourself in. You are logging the attacker in on their device.
Because the process happens on a legitimate Microsoft page, it looks completely normal. There are no fake links or misspelled web addresses to alert you. Even worse, the attack can bypass multi-factor authentication. Since the login request is genuine, security tools often see nothing unusual.
Once inside your account, hackers can read emails, open files, and contact colleagues while pretending to be you. They can also capture your session token – a kind of digital pass that keeps you logged in. Therefore, even if you change your password, they might still have access for a while.
Why traditional security tools struggle
This scam is so effective because it looks real at every step. The victim sees a trusted Microsoft page, and the login is processed through genuine systems. As a result, most standard security tools do not detect the problem.
Moreover, attackers can remain hidden by using the captured session token. They can continue accessing company data without having to log in again. This makes the attack especially dangerous for businesses that rely heavily on Microsoft 365 for daily operations.
How to protect your business from device code phishing
The best protection is awareness. Train your team to pause before entering any code or logging in from an unexpected message. If someone sends you a code to use, ask yourself: did I request this? Do I know it’s real?
If you are unsure, verify the message through another trusted method, such as a direct phone call or your internal chat system. Never rely only on the email itself. Remember, Microsoft will never ask you to enter a code that someone else provides.
From a technical point of view, your IT department or managed service provider can also help.
They should:
- Turn off device code authentication if your business does not need it.
- Create rules that allow logins only from trusted devices and safe locations.
- Regularly review and remove old or suspicious session tokens.
- Provide ongoing staff training to keep everyone alert to new types of attack.
Staying ahead of evolving cyber threats
Cyber threats such as device code phishing show how quickly online scams evolve. Therefore, your security strategy must evolve too. By combining smart technology with regular staff awareness, your business will be much harder to trick.
Get in touch with our team to find out how we can improve your cyber security setup and protect your company from attacks like device code phishing. Together, we can keep your business safe and secure.
For more guidance on how to protect your organisation, visit the National Cyber Security Centre’s advice for businesses.”
Featured Posts
View all
Tech
Windows 11 Is Getting Better Where It Really Matters
Windows 11 Improvements That Actually Save Time Windows 11 improvements are now focused on making everyday work easier…
Tech
The Simple AI Shutdown Plan That Keeps You in Control
AI Emergency Shutdown Plan That Protects Your Business An AI emergency shutdown plan is the fastest way to…
Cyber
Brutal New Microsoft Alert Scam
Brutal New Microsoft Alert Scam The Microsoft alert scam is one of the most convincing phishing tactics I…
Tech
Proven Ways Make Windows Updates Less Painful
Proven Ways to Make Windows Updates Less Painful Windows update management is less about the update itself and…