Device Code Phishing: What SMEs Need to Know

Device code phishing abuses real Microsoft logins and working MFA, leaving few warning signs. Here's what SMEs need to know in 2026.

Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering…

Read More