Notion Alerts Used to Steal Microsoft Tokens

Infosecurity Magazine · High sophistication
Last updated August 24, 2026

A financially motivated actor (“Doubloon Dredger”) abused legitimate Notion sharing notifications to trick employees into opening a PDF and completing a Microsoft device-code login flow. This allowed the attacker to harvest authentication tokens and access victim accounts without needing the password. Researchers also observed layered phishing infrastructure and links to phishing-as-a-service platforms like EvilTokens and Tycoon2FA.

Key findings

  • Attackers used fake Notion accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure.
  • Clicking the Notion notification led to an intermediary PDF with a “Review and Sign” button, which redirected to a device-code token-harvesting page (EvilTokens) disguised as an Adobe Acrobat authentication screen.
  • Victims were instructed to use a verification code on Microsoft’s legitimate device-code login flow; entering the code enabled token theft and account access.
  • Sublime identified 14 additional PDFs with overlapping links on the same button (different PDF readers could show different destinations).
  • Targets spanned multiple industries (manufacturing, telecommunications, retail, health, logistics).
  • Sublime assessed the actor likely used multiple phishing-as-a-service offerings (EvilTokens and Tycoon2FA).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Operations, IT / Identity & Access Management (IAM), Security awareness team.
  • Affected industries: Manufacturing, Telecommunications, Retail, Healthcare, Logistics.
  • Attack channels: email, website.
  • Impersonated: Senior executive at the recipient’s company (via Notion notification), Adobe Acrobat document-sharing authentication screen.

Awareness takeaways

  • Treat unexpected document-share notifications (even from trusted platforms) as suspicious and verify with the sender via a known method.
  • Be wary of PDFs that act as a gateway to sign-in pages, especially buttons like “Review and Sign” that redirect you elsewhere.
  • Do not complete device-code sign-ins (entering a code on Microsoft’s device code page) unless you personally initiated the login on a trusted device.
  • Reduce exposure by disabling or restricting device-code authentication where possible.

Red flags to watch for

  • Unexpected document-share from an executive you weren’t expecting
  • A PDF intermediary that asks you to click “Review and Sign” to proceed
  • Login flow instructs you to enter a verification code (device-code sign-in) rather than a normal sign-in
  • A third-party page providing a verification code and telling you to visit Microsoft to enter it
  • Authentication request tied to viewing a document you did not request
  • Unusual sign-in method (device code) for routine document viewing
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a Notion email: your CFO just shared a document you need to review and sign. Looks totally legit, right? But this Doubloon Dredger scam chains three steps: Notion alert, then a PDF with a big 'Review and Sign' button, then an Adobe-looking page that hands you a Microsoft device code. Here’s the twist: they tell you, 'Enter this code on Microsoft’s device-code page.' The Microsoft site is real, but entering that code hands EvilTokens and Tycoon2FA a token to your account, no password needed. If a document you weren’t expecting leads to a PDF and then tells you to enter a code on Microsoft, stop. Message the executive directly on Teams or email and confirm before you touch any code.

Similar attacks

CSuite Phish Steals M365 Sessions, Installs RMM

CSuite Phish Steals M365 Sessions, Installs RMM

Researchers observed a real phishing campaign (“CSuite”) heavily targeting U.S. organizations using familiar business-themed lures (DocuSign, Adobe, Zoom/Meet, Dropbox, Microsoft 365). After a victim engages, the attackers either steal Microsoft 365 sessions (enabling mailbox takeover and fraud) or…

September 30, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Browser Scams: ClickFix, OAuth & Session Theft

Browser Scams: ClickFix, OAuth & Session Theft

The article describes how real-world attackers are shifting common breach activity into the web browser, including phishing that steals live sessions, fake “copy/paste to fix” prompts (ClickFix), and OAuth consent/device-code tricks. It highlights how these browser-based lures can bypass MFA and…

September 30, 2026
Phishing Gets Smarter: QR Codes, Tokens, Deepfakes

Phishing Gets Smarter: QR Codes, Tokens, Deepfakes

The article describes how real-world phishing and social engineering are evolving to bypass the checks employees are trained to use (bad grammar, suspicious URLs, obvious fake login pages). It highlights specific, observed attack workflows including QR-code “device hop” phishing, OAuth token theft…

September 29, 2026
Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026