
Teams HR Phish Used Real Microsoft Login Flow
Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…
This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft accounts today, with growing risk to other platforms that support device-code flows (e.g., Salesforce, GitHub, AWS).
Device code phishing abuses the OAuth 2.0 device authorization flow, a legitimate mechanism designed for signing into devices without a keyboard or browser. An attacker generates a device code and convinces a victim to enter that code on the real sign-in page of a provider such as Microsoft, then approve the request. Because the victim is often already signed into their account when they encounter the phishing page, the approval step feels routine rather than risky. Once approved, the attacker receives valid access tokens without ever needing the victim's password.
This technique does not target the login step at all. It targets the authorization layer that comes after login, which means MFA, hardware security keys, and even passkeys do not stop it. The device code flow operates independently of how the user authenticated, so phishing-resistant credentials provide no protection once a victim is persuaded to click Allow. This is a meaningful shift from traditional credential phishing, where stronger authentication typically raises the bar for attackers.
Because victims are directed to enter codes and click approve on the legitimate provider's own domain, many standard controls, including email gateways, URL reputation checks, and network proxies, may not flag the approval action as malicious. The delivery channel can also vary widely: device code phishing pages have been distributed through email, messaging apps, social media, search engine results, and compromised websites, making channel-based filtering less reliable on its own.
While Microsoft accounts are the dominant target today, this is not limited to one vendor. Any service implementing device code flows, including Salesforce, GitHub, and AWS, can be targeted. This means the awareness problem extends across roles: sales operations and CRM admins approving a new integration, developers approving access for a tooling workflow, and IT staff handling device registration requests are all potential targets, not just general end users.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is an attack that abuses the OAuth 2.0 device authorization flow, tricking a victim into entering a code and approving access on a legitimate provider sign-in page, which grants the attacker access without needing the victim's password.
No. Because the device code flow is separate from the authentication mechanism, MFA, hardware security keys, and passkeys do not prevent this technique from succeeding.
No. While Microsoft environments are the dominant target today, any platform that supports device code flows, including Salesforce, GitHub, and AWS, can be targeted.
Because the victim interacts with legitimate provider URLs, email gateways, URL reputation tools, and network proxies may not flag or block the key approval step.
You get an email: “Action required. To finish sign-in, enter this device code on the Microsoft device login page.” Looks legit, right? Here’s the trick: this is device code phishing. You copy a short code, paste it into the real Microsoft device sign-in page, pick your account, click Allow, and you just gave them access, even with MFA or passkeys. This isn’t just Microsoft. The same device code flow has been abused against Salesforce with a fake 'DataLoader' app, and can hit GitHub, AWS, anything that uses device codes. The aha: they’re not stealing your password, they’re tricking you into approving their app. So your move: if you’re ever asked to enter a device code or approve a new app you didn’t start, on Microsoft, Salesforce, GitHub, anything, stop and ping IT on Teams before you hit Allow.

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…

Attackers abused Microsoft’s OAuth “device code” sign-in so victims completed a real Microsoft login and MFA, but the resulting session tokens were issued to…

Attackers trick employees into entering a short “device code” on a real Microsoft sign-in page (microsoft.com/devicelogin), causing Microsoft 365 to issue…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

Researchers found a live Microsoft 365 phishing server accidentally left open with directory listing enabled, exposing phishing configs, stolen credential…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…