
Device Code Phishing: MFA Bypass at Scale
This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…
Researchers found attackers taking over hotel and conference-center Wi‑Fi gateways and silently redirecting guests to fake Microsoft 365 sign-in pages to steal credentials. In some cases, the attackers also tried to route broader device traffic through a malicious proxy (WPAD) or trick users into approving Microsoft “device-code” sign-ins, which can bypass passwords and MFA.
Researchers at ReliaQuest found that attackers were compromising Wi-Fi gateways at hotels and conference centers used by traveling corporate employees. Because the attackers controlled the gateway, they had control over DNS resolution for anyone connected to that network. This let them quietly redirect victims to attacker-controlled infrastructure without any obvious change to the address bar or browsing experience. Once redirected, victims landed on lookalike Microsoft 365 sign-in pages hosted on domains such as m365-owa.com and ms365-live.com.
In a smaller subset of cases, attackers skipped credential theft entirely and instead targeted Microsoft's device-code sign-in flow, tricking users into approving a login that actually belonged to the attacker. Approving that prompt hands over a valid, MFA-cleared session token with no password required. In roughly a third of the observed cases, attackers also attempted to abuse Windows' automatic proxy discovery feature (WPAD) to route broader application traffic through their own proxy.
The attack works because it exploits trust in the underlying network rather than tricking users through an obvious phishing email. Since DNS is controlled at the gateway level, users can be redirected even when everything else about their session looks normal. Employees connecting to hotel or conference Wi-Fi generally expect a captive portal or login screen, which primes them to enter credentials without close scrutiny of the domain or certificate. The device-code approval technique is especially effective because it does not require stealing a password at all, it only requires the victim's brief cooperation.
These controls target the specific mechanics of the attack, cutting off DNS manipulation at the network layer while also addressing the human decision point where a device-code prompt or fake login page is presented.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromised Wi-Fi gateways at hotels and conference centers and used DNS control to silently redirect users to lookalike Microsoft login pages such as m365-owa.com and ms365-live.com.
Yes, in some cases attackers targeted Microsoft's device-code sign-in flow, tricking users into approving a login and handing over an MFA-cleared session token without needing a password.
In roughly a third of observed cases, attackers abused Windows' automatic proxy discovery feature (WPAD) to route broader application traffic through an attacker-controlled proxy.
A full-tunnel VPN that routes all DNS through the corporate tunnel before the network gateway can intercept it, combined with training to check certificates and deny unexpected sign-in approvals, are effective defenses.
You connect to hotel Wi‑Fi, and boom, before your email even loads, a Microsoft 365 login page pops up. Researchers found hotel and conference Wi‑Fi gateways hijacked so they can quietly redirect you to fake Microsoft pages like m365-owa.com or ms365-live.com, even when the web address bar looks normal. In some cases they skip passwords entirely, abusing Microsoft’s device-code sign-in: you see an approval prompt on hotel Wi‑Fi that you didn’t start, and if you click approve, they get a valid, MFA-cleared session. On hotel or conference Wi‑Fi, if a Microsoft 365 login or approval pops up that you didn’t expect, stop and open our full-tunnel VPN first, then only sign in through pages you browse to yourself.

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access…

Attackers sent emails that looked like Microsoft Teams/HR notifications and pushed users through Microsoft’s real sign-in and OAuth consent screens. When…

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Attackers are compromising hotel and conference center Wi‑Fi gateways and changing DNS settings so business travelers are silently redirected to fake Microsoft…

Researchers report attackers compromising hotel and conference Wi‑Fi gateway equipment to silently redirect travelers to fake Microsoft 365 sign-in pages,…

ReliaQuest reports attackers are compromising public Wi‑Fi “captive portal” gateways (such as in hotels and conference centers) and changing their DNS settings…