
Device Code Phishing: MFA Bypass at Scale
This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…
A scammer impersonated the Democratic National Committee chair and convinced a staffer to send nearly $29,000. The DNC detected the issue within minutes, but only recovered part of the funds. This is a classic business email compromise (BEC) pattern: a trusted executive identity is used to pressure staff into making a payment.
A scammer impersonated the chairman of the Democratic National Committee and emailed a staffer with an urgent payment request. The staffer, believing the message came from a senior leader, sent nearly $29,000 to an account provided in the email. The DNC identified the problem within minutes and alerted its bank, Wells Fargo, but only recovered $7,000 of the funds. The organization later described the loss to federal regulators as a misdisbursement caused by outside fraud and said it would take further steps to prevent a repeat.
This incident follows a classic business email compromise pattern. A few factors made it effective even against a staff that reportedly receives fraud training:
The attack did not rely on technical sophistication. It relied on the natural instinct to comply quickly with a request that appears to come from someone in authority, especially when framed as urgent and routine.
This type of scam targets anyone who can initiate or approve payments, including finance and operations staff, executive assistants, and leadership teams. Political and campaign organizations across parties have reportedly faced similar BEC-style fraud attempts, suggesting this is a recurring risk pattern for the sector rather than an isolated case.
Defenders should be alert to:
Organizations can reduce exposure to this kind of fraud by treating any emailed money-movement request, particularly one attributed to an executive, as high risk until verified through a separate, trusted channel such as a phone call to a known number rather than a reply to the email itself. If a fraudulent transfer is suspected, speed matters: notifying the bank and internal finance or security teams quickly, as the DNC reportedly did within minutes, can improve the odds of recovering funds, even if only partially. Finally, incidents like this are a reason to revisit training and tighten approval steps, since even staff with existing fraud training and security protocols can still be targeted successfully by a well-timed impersonation attempt.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
An attacker impersonated the DNC chairman in an email to a staffer and pressured them into sending nearly $29,000 to an outside account.
The DNC caught the issue within minutes and contacted its bank, Wells Fargo, but only recovered $7,000 of the nearly $29,000 sent.
They rely on urgency and authority from a trusted leader, and the payment instructions were delivered only over email without a verified callback.
Verify any emailed payment request through a known, trusted channel such as a phone call to a verified number, and tighten approval steps after any incident.
Picture this: an email that looks like it’s from your chair, “I need you to handle a quick payment for me today.” That exact scam hit the Democratic National Committee. Someone impersonated chair Ken Martin and a staffer sent nearly twenty-nine thousand dollars, only seven thousand was recovered. The red flags were there: unexpected urgency from a senior leader, payment instructions only over email, and a first-time account for a rushed transfer, classic business email compromise. Your move: if any email asks you to move money, stop and call the sender on a known number before you touch the transfer.

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed,…

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into…

A threat landscape report describes how criminals now buy or rent phishing, fraud, malware, and hidden infrastructure “as a service,” making scams faster to…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…

Researchers described a long-running fraud campaign where criminals clone real Russian company websites and replace contact and bank details to intercept…