
Device Code Phishing: MFA Bypass at Scale
This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…
The article describes how social engineers can use cheap, online-ordered lookalike lanyards, ID badges, uniforms, and PPE to appear legitimate and gain physical access to facilities. It’s based on real physical security engagements where testers used convincing “visual tokens of trust” (badges, branded clothing, key fobs, letterhead) to reduce suspicion. The main lesson is that appearance is not identity, staff must consistently verify unfamiliar people even when they look the part.
This breakdown is based on real physical security engagements where testers used branded lanyards, ID badges, uniforms, hard hats, key fobs, and corporate materials to appear legitimate. None of these items alone guaranteed entry. Instead, the combination of a credible badge, matching clothing, and a plausible reason for being onsite was often enough to avoid scrutiny at reception, doors, and turnstiles.
The items themselves were not sophisticated. Online suppliers make it easy to order or produce convincing copies of badges, lanyards, and branded apparel using nothing more than logos and photos found publicly. This keeps the attack sophistication low while the payoff, unchallenged physical access, remains high.
The core weakness is that appearance was treated as a substitute for verified identity. When someone looks the part, staff are less likely to ask questions, especially if the person offers a simple, believable reason for being there. Multiple small trust signals stacking together, badge plus clothing plus props, created enough social proof to bypass normal access procedures like badge scans, sign-in, or escort requirements.
This technique aligns with T1656, impersonation, and applies to any organization with physical offices or sites that use badges, uniforms, PPE, or branded access-control apparel.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
According to the source, online suppliers make it easy to order or create convincing copies of lanyards, ID badges, branded clothing, and PPE using public logos and photos, often in small quantities.
No, the article notes that no single item gets someone through the door, but combined trust signals like a badge, matching clothing, and a plausible reason for being there can be enough to avoid scrutiny.
Anti-counterfeit features such as holograms, unique colors or materials, and controlled vendors can raise attacker cost, but staff still need to challenge unfamiliar people and follow access procedures every time.
The targeted audience includes reception, security, facilities, office staff, and operations or site leads, since any of these roles could be the point where an unverified person is let through.
That person in the perfect company hoodie and shiny badge? They might have ordered all of it online last night. On real security tests, teams have walked in using fake badges, uniforms, hard hats, even key fobs, no single item is perfect, but together they make you look like you belong. They walk up and say, “Hi, I’m here for work onsite today,” and people wave them through because the badge, clothing, and story feel right, even when the badge never gets scanned and the name isn’t checked. Here’s the rule: appearance is not identity. If you don’t personally know them, don’t wave them through, use the normal process every time: scan the badge, check the name, or call for an escort.

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Researchers reported a real malware campaign where attackers trick people searching for Flash Player into installing a fake “Flash” installer that delivers the…

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The…

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because…

Researchers investigated a fake Android app posing as a Chinese public security bureau service and traced it to a broader criminal ecosystem using a leaked…

Attackers compromised hundreds of legitimate websites and injected code that sent visitors to a fake Cloudflare page. The fake page used a “ClickFix” trick to…