
Device Code Phishing: MFA Bypass at Scale
This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…
Attackers abused Microsoft’s OAuth “device code” sign-in so victims completed a real Microsoft login and MFA, but the resulting session tokens were issued to the attacker. In a documented Microsoft 365 takeover, the attacker used a believable partner-law-firm email thread and a Google Sites lure page to get the victim to enter a verification code on Microsoft’s legitimate sign-in page. After approval, the attacker signed in from abroad, registered rogue devices, and created hidden mailbox rules to maintain access and spread more phishing.
This Microsoft 365 takeover did not start with a suspicious link. It started with a conversation. The attacker posed as a partner from a law firm and opened with a friendly note about a possible collaboration, exchanging several messages with the victim before ever sending a link. Only after that rapport was built did the attacker send a document-sharing link.
The link led to a page hosted on Google Sites, a trusted platform, and used redirect chains through compromised legitimate sites to slip past URL filtering. The final landing page sat behind a fake human-check prompt to keep automated scanners away. It looked like a normal document-sharing portal, but instead of a document, it displayed a short verification code and instructed the victim to enter it at Microsoft's real sign-in page.
This is the core of device-code phishing. The victim was completing a genuine Microsoft login and a genuine MFA approval. But approving that code handed the attacker a valid session token, not the victim.
The attack succeeded because nothing about the actual login experience looked wrong. The page where the victim entered credentials really was Microsoft's site. The only unusual element was a short code and a plausible reason to enter it, embedded in a believable business conversation about collaboration. There was no fake login page for a trained eye to catch, no obvious spoofed domain, just a normal-seeming request layered on top of a legitimate authentication flow.
Once the attacker had a valid session, the activity moved into the cloud rather than the endpoint. Findings from this case included:
Because the intrusion occurs at the identity layer, that is where defenders need to look for signals, not on the endpoint.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a technique where attackers abuse Microsoft's OAuth device code sign-in flow so a victim enters a short code on Microsoft's genuine sign-in page, which satisfies MFA and issues a valid session token to the attacker instead of the victim.
The attacker posed as a law firm partner, built trust through a multi-message email conversation, then sent a document-sharing link built on Google Sites that displayed a verification code and walked the victim through entering it at Microsoft's real sign-in page.
Because the victim completed a genuine Microsoft login and MFA approval themselves. The session tokens generated by that real login were issued to the attacker, so no password or MFA code was actually stolen.
Disable the OAuth device-code flow via Conditional Access where it is not needed, monitor for device-code sign-ins and mailbox rule changes, and train users to treat any unexpected request to enter a code as a red flag.
You get an email from a law firm partner, friendly back‑and‑forth all week… then they send a document link. You click. It goes through a Google Sites page and a couple of redirects, then lands on a document-looking portal that shows a short code and says: enter this on Microsoft to verify. You do it on the real Microsoft sign-in page, approve MFA, everything looks normal. But that code actually approves the attacker’s device, so they log in from abroad, register rogue devices, and hide their emails with mailbox rules. If someone ever asks you to enter a random code to view a document, stop. Don’t enter it, forward that email to security and confirm through our usual channel instead.

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…