York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Device Code Phishing Just Went Mainstream — and It Walks Right Past Your Microsoft 365 MFA

York Computer

Security researchers reported this week that device code phishing — a Microsoft 365 attack that steals access tokens without ever touching a password — has officially gone mainstream. Eighteen kits, a 37x spike in detections, and every major AiTM vendor adding it to their platform means the technique has graduated from nation-state espionage to commodity crime in a matter of months. If your business runs on Microsoft 365 — and most York County small businesses do — this attack is built to walk right past the MFA you're relying on.

What device code phishing actually is

Device code phishing abuses a legitimate Microsoft sign-in feature designed for things like printers, smart TVs, and conference room displays that can't easily show a full login screen. The feature lets a user see a short code, visit Microsoft's device login page on another device, sign in, and authorise access. Attackers hijack that flow. They email an employee a short code and tell them to enter it at Microsoft's real login page. The employee does, completes their MFA challenge as usual — and unknowingly hands the attacker a valid access token to their account.

The critical part: multifactor authentication provides no protection against this attack class. The victim completes the MFA challenge themselves on behalf of the attacker, and the resulting refresh tokens persist even after a password reset, complicating remediation. Changing the password after the fact does not kick the attacker out.

Why this week's news matters

Through 2025 and early 2026, device code phishing was mostly an advanced-actor technique. That changed fast. Researchers tied the spike to publicly released criminal toolkits and the emergence of multiple phishing-as-a-service (PhaaS) offerings. Earlier campaigns documented by Huntress already hit more than 340 organizations across the U.S., Canada, Australia, New Zealand, and Germany, with construction, non-profits, real estate, manufacturing, financial services, healthcare, legal, and government among the most-targeted sectors. Those are exactly the industries that fill York County's main streets and industrial parks.

Once attackers have the token, the damage compounds. They access M365 accounts directly, take over accounts, steal sensitive data, and move across networks. From there, the typical playbook is invoice fraud, wire-transfer redirection, and pivoting into SharePoint, OneDrive, and Teams to find more victims inside the same company or its customers.

What your managed-IT provider should be doing right now

Standard MFA prompts and basic awareness training are not enough for this one. A serious provider should already be taking these steps as part of a proper managed IT and security stack:

- **Disable or restrict the OAuth 2.0 device authorization flow** in Microsoft Entra ID Conditional Access for users who don't need it. Most office staff never legitimately use it. - **Enforce phishing-resistant MFA** (FIDO2 security keys or Windows Hello for Business) for admins and high-value accounts. - **Set short token lifetimes and sign-in frequency policies** so a stolen refresh token expires fast. - **Monitor Entra sign-in logs** for device code authentications from unusual locations, unusual client IDs, or off-hours activity — and alert on them. - **Have a token-revocation runbook**: if an account is suspected, revoke all refresh tokens immediately, not just reset the password. - **Train users on the specific lure**: if anyone — vendor, IT, a Teams message, a PDF — asks them to enter a code on a Microsoft login page, stop and call IT.

If your current IT support can't explain whether device code flow is restricted in your tenant, that's the conversation to have this week.

What York Businesses Should Do

York County businesses in construction, manufacturing, legal, healthcare, and accounting are squarely in the target profile for this campaign. If you're a York Computer client, your Microsoft 365 Conditional Access policies already account for device code abuse — if you're not, ask your provider for written confirmation that device code flow is blocked or restricted for your users.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles