‹ Back to Home

A New Phishing Attack Bypasses Your Password AND Your OTP — And It's Grown 37x This Year

There's a phishing attack spreading rapidly in 2026 that defeats two-factor authentication entirely. It doesn't steal your password — it tricks you into authorising the attacker's device using a legitimate Microsoft login page. It's grown 37.5 times in volume since early this year, and India's corporate Microsoft 365 users are directly in the target zone.

Keerthika 7 min read 581
Follow on Google
Updated 5 months ago
Security A New Phishing Attack Bypasses Your Password AND Your OTP — And It's Grown 37x This Year 7 min left Follow on Google
A New Phishing Attack Bypasses Your Password AND Your OTP — And It's Grown 37x This Year

TamilTech AI summary

A sneaky new phishing wave called device code phishing is bypassing both your password and your OTP by tricking you into entering a real Microsoft device code on the real microsoft.com/devicelogin page, which hands attackers lasting access tokens to your Microsoft 365 account. It abuses the OAuth device authorization flow meant for TVs and IoT gadgets, so after you sign in and complete 2FA the attacker—not you—gets the access and refresh tokens for Outlook, Teams, SharePoint, and OneDrive, and those tokens often stay valid even after a password change. Attacks have exploded about 37.5 times in 2026 because phishing-as-a-service kits like EvilTokens, VENOM, and others let less-skilled criminals run polished campaigns with fake Teams, DocuSign, or shared-document lures. Anyone on Microsoft 365 is a target, and Indian IT, BPO, finance, and startup teams face extra risk because a single compromised account can expose client data, enable big business-email-compromise fraud, and create DPDPA liability. Never enter a device code you did not start yourself on a real device, treat unsolicited “verify this code” emails as hostile, and have IT disable device-code flow where it is not needed, tighten Entra ID Conditional Access, and revoke OAuth tokens directly if an account is hit.

  • Device code phishing grew 37.5x in 2026 — EvilTokens PhaaS kit made it accessible to low-skill criminals; 11+ competing kits now in circulation
  • Attack bypasses both password AND 2FA — victim enters real credentials on real Microsoft page; tokens remain valid even after password reset
  • Indian Microsoft 365 corporate users at risk: IT teams must disable device code flow for non-device users and revoke OAuth tokens — password reset alone is insufficient

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

This attack bypasses your OTP — and that's what makes it dangerous

Most people now know the basic phishing drill: don't click suspicious links, don't enter your password on fake websites, enable two-factor authentication. That last step — 2FA, the OTP that comes to your phone — is supposed to be the safety net that catches you even if everything else goes wrong.

There's a phishing technique that defeats 2FA completely. Not by hacking your phone. Not by intercepting your OTP. But by getting you to voluntarily enter a legitimate code on a legitimate Microsoft website — and unknowingly handing the attacker permanent access to your account in the process. This attack, called device code phishing, has grown 37.5 times in volume in 2026 compared to early last year. Security researchers tracking it describe the growth as explosive.

If you or your organisation uses Microsoft 365 — Outlook, Teams, SharePoint, OneDrive — you need to understand exactly how this works.

What device code phishing actually is — explained simply

OAuth 2.0 is the login system that powers most modern apps. When you sign into a service via Google or Microsoft, OAuth is handling the authentication behind the scenes. One specific part of OAuth is called the Device Authorization Grant — it was designed for devices that don't have keyboards, like smart TVs, printers, IoT sensors, and streaming boxes. When you log into Netflix on your TV, the TV shows you a code and asks you to visit a website on your phone to enter it. That's the device code flow.

Attackers realised this flow could be weaponised. Here's how the attack actually works, step by step.

The attacker sends a request to Microsoft's servers asking for a device code. Microsoft responds with a legitimate code — something like ABCD-1234. The attacker then sends you an email pretending to be Microsoft Teams, Adobe, DocuSign, SharePoint, or even a construction bid notification. The email says you need to verify your identity or access a shared document — and asks you to visit the real Microsoft login page at microsoft.com/devicelogin and enter the code provided.

You go to the real Microsoft website. You enter your actual Microsoft credentials. You complete your 2FA — your OTP arrives and you enter it. Microsoft verifies everything correctly, creates an access token and a refresh token, and hands them to whoever holds the device code.

That's the attacker. They now have your access token and refresh token — giving them full access to your Microsoft 365 account. Email, Teams messages, SharePoint files, OneDrive documents — everything. And here's the worst part: these tokens remain valid even if you change your password later. A password reset doesn't revoke the tokens the attacker already holds.

Why it's exploded in 2026 — phishing-as-a-service kits

Device code phishing isn't new — it was first documented in 2020 and has been used by state-sponsored hackers and financially motivated criminal groups since then. What's changed in 2026 is accessibility. A kit called EvilTokens emerged as a phishing-as-a-service (PhaaS) platform — meaning less technically skilled criminals can now run sophisticated device code phishing campaigns without understanding the underlying OAuth mechanics. They just subscribe to EvilTokens, pick a lure template, and run campaigns.

EvilTokens isn't alone. At least 11 different competing kits are now in circulation. VENOM offers device code phishing alongside adversary-in-the-middle capabilities. SHAREFILE uses document transfer themes to trick corporate employees into entering codes. CLURE uses SharePoint-themed lures with anti-bot protection and infrastructure hosted on DigitalOcean. LINKID uses Microsoft Teams and Adobe themes through Cloudflare pages. AUTHOV uses Adobe document-sharing lures. Each kit competes for the same criminal market, offering slightly different evasion techniques and lure templates.

The scale is already significant: one documented campaign targeted over 340 Microsoft 365 organisations across the United States, Canada, Australia, New Zealand, and Germany — using construction bid lures, DocuSign impersonation, voicemail notifications, and Microsoft Forms pages, all routing through the same Railway.com infrastructure. The campaign was first spotted on February 19, 2026, and cases have been appearing at accelerating pace since then.

Why Indian corporate users are particularly at risk

India has one of the largest Microsoft 365 user bases in the world. The platform is standard in IT services companies, BPO operations, financial services firms, healthcare providers, and government contractors. Infosys, Wipro, TCS, HCL, and thousands of smaller IT firms across Chennai, Bangalore, Hyderabad, and Pune run their entire internal communication and document infrastructure on Microsoft 365.

Device code phishing attacks don't require targeting India specifically — they target organisations with Microsoft 365 accounts globally, and India's corporate users are part of that global pool. A campaign using a DocuSign-themed lure or a "shared document" notification is convincing to anyone doing corporate work, regardless of geography. The financial stakes are high: a compromised Microsoft 365 account at an IT services company gives attackers access to client project data, internal HR information, financial documents, and email communication that can be used for business email compromise fraud — a scam that regularly results in fraudulent wire transfers of lakhs to crores of rupees.

For Indian startups using Microsoft Teams as their primary communication tool, a compromised account could expose investor communications, product roadmaps, customer data, and employment contracts. The DPDPA (Digital Personal Data Protection Act) creates regulatory liability for organisations that suffer data breaches — making a Teams or SharePoint compromise significantly more consequential than it might have been two years ago.

How to tell if you're being targeted — the warning signs

Device code phishing emails are convincing precisely because they direct you to real Microsoft pages. The attack doesn't involve a fake login page — that's what makes it so hard to catch. However, there are red flags to watch for.

The first red flag: you receive an unsolicited email asking you to enter a code at microsoft.com/devicelogin when you didn't initiate any login or device connection yourself. Legitimate device code prompts only appear when you're physically trying to connect a new device to your account — your TV, printer, or streaming device. If you get an email with a code and you're not connecting a device right now, treat it as an attack.

The second red flag: urgency language. "Your account will be suspended," "Document expires in 24 hours," "Verify immediately." These are classic social engineering pressure tactics designed to get you to act before you think.

The third red flag: the email domain doesn't match the service. A DocuSign notification should come from docusign.com, not docusign-notifications.net or similar lookalike domains.

What your IT team needs to do right now

For individuals, the defence is awareness — never enter a device code you didn't personally generate by connecting a device. For organisations, the technical responses are more specific. Microsoft allows administrators to disable the device code flow entirely for accounts that don't need it — most corporate employees never connect smart TVs or IoT devices to their Microsoft 365 accounts, so disabling this flow removes the attack surface completely. Conditional Access policies in Microsoft Entra ID (formerly Azure AD) can restrict which devices and locations are allowed to complete device code authentication. Monitoring for unusual token grants in the Microsoft Entra audit logs can detect successful attacks that got past user awareness.

The critical point about token revocation: changing your password is not enough if you've already completed a device code phishing attack. Your IT team needs to revoke the OAuth tokens directly through the Microsoft Entra admin portal — Settings, then Users, then the affected account's active sessions — to invalidate the attacker's access.

TamilTech's take

The 37x growth in device code phishing is a direct consequence of the phishing-as-a-service economy — where criminal infrastructure is productised and sold by subscription, lowering the technical barrier for running sophisticated attacks to near zero. EvilTokens and its competitors are effectively turning account takeover into a commodity service. For Indian corporate IT teams managing Microsoft 365 deployments, this is the security alert of Q1 2026. The attack defeats password security and 2FA simultaneously, targets real Microsoft infrastructure so URL-checking offers no protection, and leaves attackers with persistent access that survives a password reset. Review your Entra ID policies, disable device code flow for users who don't need it, and train your teams to never enter a device code they didn't personally generate.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,346 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications