Notion Alerts Used to Steal Microsoft Tokens

Infosecurity Magazine · High sophistication
Last updated August 24, 2026

A financially motivated actor (“Doubloon Dredger”) abused legitimate Notion sharing notifications to trick employees into opening a PDF and completing a Microsoft device-code login flow. This allowed the attacker to harvest authentication tokens and access victim accounts without needing the password. Researchers also observed layered phishing infrastructure and links to phishing-as-a-service platforms like EvilTokens and Tycoon2FA.

Key findings

  • Attackers used fake Notion accounts impersonating senior executives to send document-sharing notifications from legitimate Notion infrastructure.
  • Clicking the Notion notification led to an intermediary PDF with a “Review and Sign” button, which redirected to a device-code token-harvesting page (EvilTokens) disguised as an Adobe Acrobat authentication screen.
  • Victims were instructed to use a verification code on Microsoft’s legitimate device-code login flow; entering the code enabled token theft and account access.
  • Sublime identified 14 additional PDFs with overlapping links on the same button (different PDF readers could show different destinations).
  • Targets spanned multiple industries (manufacturing, telecommunications, retail, health, logistics).
  • Sublime assessed the actor likely used multiple phishing-as-a-service offerings (EvilTokens and Tycoon2FA).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, Operations, IT / Identity & Access Management (IAM), Security awareness team.
  • Affected industries: Manufacturing, Telecommunications, Retail, Healthcare, Logistics.
  • Attack channels: email, website.
  • Impersonated: Senior executive at the recipient’s company (via Notion notification), Adobe Acrobat document-sharing authentication screen.

Awareness takeaways

  • Treat unexpected document-share notifications (even from trusted platforms) as suspicious and verify with the sender via a known method.
  • Be wary of PDFs that act as a gateway to sign-in pages, especially buttons like “Review and Sign” that redirect you elsewhere.
  • Do not complete device-code sign-ins (entering a code on Microsoft’s device code page) unless you personally initiated the login on a trusted device.
  • Reduce exposure by disabling or restricting device-code authentication where possible.

Red flags to watch for

  • Unexpected document-share from an executive you weren’t expecting
  • A PDF intermediary that asks you to click “Review and Sign” to proceed
  • Login flow instructs you to enter a verification code (device-code sign-in) rather than a normal sign-in
  • A third-party page providing a verification code and telling you to visit Microsoft to enter it
  • Authentication request tied to viewing a document you did not request
  • Unusual sign-in method (device code) for routine document viewing
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a Notion email: your CFO just shared a document you need to review and sign. Looks totally legit, right? But this Doubloon Dredger scam chains three steps: Notion alert, then a PDF with a big 'Review and Sign' button, then an Adobe-looking page that hands you a Microsoft device code. Here’s the twist: they tell you, 'Enter this code on Microsoft’s device-code page.' The Microsoft site is real, but entering that code hands EvilTokens and Tycoon2FA a token to your account, no password needed. If a document you weren’t expecting leads to a PDF and then tells you to enter a code on Microsoft, stop. Message the executive directly on Teams or email and confirm before you touch any code.

Similar attacks

Copy-Paste Lures Spread New macOS & Windows RATs

Copy-Paste Lures Spread New macOS & Windows RATs

This report describes real-world social engineering where victims are tricked into copying and pasting commands that install malware on macOS and Windows. It also highlights device code phishing activity targeting Microsoft Entra ID/Microsoft 365 tokens, enabling attackers to access accounts and…

August 20, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
Russian Clusters Abuse Login Flows to Steal Accounts

Russian Clusters Abuse Login Flows to Steal Accounts

Google says three suspected Russian espionage clusters are targeting academics, think tanks, diplomats, and related nonprofit staff by abusing legitimate login and verification workflows that may not look like “classic phishing.” The campaigns include app-password scams, OAuth/device-code tricks,…

August 20, 2026
Greatness PhaaS Adds Device-Code MFA Bypass

Greatness PhaaS Adds Device-Code MFA Bypass

Criminals using the “Greatness” phishing-as-a-service kit are running real-world phishing campaigns that trick employees into approving a Microsoft device-code login flow, allowing attackers to bypass MFA and steal access tokens. Recent activity includes RingCentral “voicemail” lures and multi-step…

August 4, 2026
Hacked Wi‑Fi Portals Steal M365 Logins

Hacked Wi‑Fi Portals Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where attackers tampered with public Wi‑Fi captive portal networks (hotels/conference venues) to redirect users to attacker-controlled pages. The goal was to steal Microsoft 365 credentials (and sometimes deliver malware) by using…

August 3, 2026
Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026