Device Code Phishing: What SMEs Need to Know
Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering known as device code phishing.
Because the login page is genuine and multi-factor authentication (MFA) completes exactly as it should, most of the warning signs businesses train staff to look for simply aren’t there. Here is what every SME should know about this technique.
1. It Exploits Legitimate Business Workflows

The same short-code login used for streaming devices is now a business social engineering vector.
The most dangerous part of device code phishing is that it hides inside a business workflow employees already use without a second thought.
If you’ve ever signed into Netflix on a new TV, linked Spotify to a games console, or activated a device using a short on-screen code, you’ve already used device code authentication — technically, the OAuth 2.0 “device authorization grant.” Instead of typing a password on an awkward remote control, you’re shown a short code, you enter it on the service’s genuine login page on a device where you’re already signed in, and the new device connects. It takes seconds, and it’s something millions of people do without thinking twice.
Now imagine an employee receives a Microsoft Teams meeting invitation from what looks like a customer, supplier, or colleague. During the exchange, they’re told they need to authenticate a device — one a threat actor actually controls — before joining the call or accessing shared documents. They’re given a short code and pointed to Microsoft’s genuine device sign-in page. Nothing looks wrong, because the website really does belong to Microsoft and the authentication step really is genuine. The only thing an attacker has inserted is the story around the request — exactly the technique Microsoft attributed to Storm-2372, a group Microsoft assesses with medium confidence to be aligned with Russian state interests, which used fake Teams and messaging-app invitations to target government, NGO, IT, defence, telecoms, health, and energy organisations across Europe, North America, Africa, and the Middle East from mid-2024 onward.
Other pretexts work just as well: an employee is told they need to re-authenticate Microsoft 365 after a security update, reconnect Outlook following a mailbox migration, authorise a new Teams integration, or complete a sign-in requested by “IT.” As attackers increasingly exploit trusted business processes instead of building fake infrastructure, security awareness has to keep pace.
2. MFA Doesn’t Stop Device Code Phishing
For many SMEs, switching on multi-factor authentication across critical accounts is one of the first serious cybersecurity improvements they make — and rightly so. MFA remains one of the most effective defences against stolen passwords, credential stuffing, and password reuse after a data breach. If your business hasn’t enabled it everywhere it can be, that should still be the priority.
The risk is treating MFA as the finish line rather than one layer of defence. Device code phishing doesn’t defeat MFA technically, and it doesn’t trick anyone into revealing a one-time code. Employees complete the MFA challenge exactly as designed — the problem is that they complete it as part of a device-authorization request the attacker started, not one they intended. From the identity provider’s point of view, everything happened correctly: the user proved who they are and approved access. The attacker simply collects the resulting access token instead of the employee’s own device receiving it.
As password hygiene and MFA adoption have both improved, attackers have looked past authentication itself. Rather than break down the front door, they’re persuading someone already inside to hand over a legitimate key.
3. It’s No Longer Just Nation-State Tradecraft

What started as nation-state tradecraft is now sold as a subscription.
Not long ago, device code phishing was largely the preserve of sophisticated state-aligned actors like Storm-2372. Researchers at Volexity separately linked at least two more Russia-affiliated clusters to the same technique around the same period, suggesting the tradecraft spread through espionage circles before it reached ordinary cybercrime.
That changed during 2026. Proofpoint recorded a sharp rise in device code phishing activity from September 2025 onward, and by March 2026 the cybercriminal group it tracks as TA4903 — previously known for business email compromise — had shifted to using device code phishing almost exclusively. The catalyst was commoditisation: phishing-as-a-service platforms such as EvilTokens (which launched on Telegram in February 2026), Tycoon2FA (an established adversary-in-the-middle kit whose operators pivoted to device code phishing after a March 4, 2026 Europol-led takedown of the platform), and Kali365 (a subscription kit sold since April 2026) now package most of the attack chain, letting operators with little understanding of OAuth or identity protocols run campaigns of their own.
The scale is stark. Push Security tracked a 15-fold increase in detected device code phishing pages at the start of March 2026, rising to 37.5 times previous levels within weeks as more kits entered circulation. Barracuda separately detected more than seven million device code phishing attacks over a single four-week period in April 2026, and Push Security now tracks more than two dozen distinct kits in active use.
The same pattern played out earlier with ransomware, adversary-in-the-middle phishing, and business email compromise: once a technique is packaged and sold, it reaches opportunistic criminals targeting businesses of every size, not just the high-value targets nation-state actors go after. Device code phishing has now reached that point, which means SMEs should assume they may encounter it sooner than expected.
4. Security Awareness Needs to Evolve

The new question employees need to ask isn’t “is this a fake page?” — it’s “did I request this?”
Phishing awareness training usually teaches employees to check for familiar red flags: hover over links before clicking, watch for spelling mistakes, confirm a login page belongs to the company it claims to represent. Those lessons remain useful and continue to stop plenty of attacks.
But most of that training boils down to one instruction: don’t give away your credentials. Don’t type your password into a suspicious site. Don’t read out a one-time code. Device code phishing introduces a different behaviour employees need to recognise — being asked to authorise a device on somebody else’s behalf.
Today’s identity attacks increasingly target user approval rather than user secrecy. Whether it’s consenting to an OAuth application, approving an unexpected MFA prompt, or completing a device authorization flow, the attacker is trying to persuade the user to perform a perfectly legitimate action that ultimately benefits someone else. Phishing simulations that only test whether staff click a malicious link or enter credentials into a cloned page remain valuable, but they don’t prepare anyone for an attack that succeeds through a completely legitimate workflow. Awareness has to evolve alongside the technique.
Prepare Employees for the Next Wave of Device Code Phishing

Realistic, current attack scenarios build the habit of questioning an unexpected request.
Cybercriminals keep adapting their social engineering to match the way people actually work, and device code phishing is a clear example — it exploits a trusted authentication workflow rather than a fake website or a stolen password. That’s exactly why realistic phishing simulations remain one of the most effective ways for SMEs to strengthen their human defences.
By exposing employees to realistic, current attack scenarios — including emerging techniques like device code phishing — businesses can build the habit of questioning an unexpected authorization request before it turns into an account takeover. DIESEC’s phishing simulation programme tests your team against the latest real-world attack patterns, backed by targeted training and awareness sessions.

