Device Code Phishing: What SMEs Need to Know

Device code phishing abuses real Microsoft logins and working MFA, leaving few warning signs. Here's what SMEs need to know in 2026.

Cybercriminals have started exploiting a login shortcut millions of people already trust. Rather than sending victims to a fake login page or trying to steal a password outright, they persuade employees to authorise an attacker-controlled device through a completely legitimate identity provider — Microsoft, most often. The result is a fast-growing form of social engineering…

Read More

Identity Theft in Germany: What SMEs Need to Know

Identity theft and stolen credentials drive most cybercrime in Germany

Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in…

Read More

Azure CLI Password Spray Bypasses MFA

Azure CLI Password Spray

An Azure CLI password spray campaign made more than 81 million login attempts against Microsoft accounts over two weeks and successfully compromised 78 accounts across 64 organizations — a meaningful share of which believed multi-factor authentication already protected them. The attackers did not break MFA. They found a legacy authentication path that most Conditional Access…

Read More