This attack bypasses your OTP — and that's what makes it dangerous
Most people now know the basic phishing drill: don't click suspicious links, don't enter your password on fake websites, enable two-factor authentication. That last step — 2FA, the OTP that comes to your phone — is supposed to be the safety net that catches you even if everything else goes wrong.
There's a phishing technique that defeats 2FA completely. Not by hacking your phone. Not by intercepting your OTP. But by getting you to voluntarily enter a legitimate code on a legitimate Microsoft website — and unknowingly handing the attacker permanent access to your account in the process. This attack, called device code phishing, has grown 37.5 times in volume in 2026 compared to early last year. Security researchers tracking it describe the growth as explosive.
If you or your organisation uses Microsoft 365 — Outlook, Teams, SharePoint, OneDrive — you need to understand exactly how this works.
What device code phishing actually is — explained simply
OAuth 2.0 is the login system that powers most modern apps. When you sign into a service via Google or Microsoft, OAuth is handling the authentication behind the scenes. One specific part of OAuth is called the Device Authorization Grant — it was designed for devices that don't have keyboards, like smart TVs, printers, IoT sensors, and streaming boxes. When you log into Netflix on your TV, the TV shows you a code and asks you to visit a website on your phone to enter it. That's the device code flow.
Attackers realised this flow could be weaponised. Here's how the attack actually works, step by step.
The attacker sends a request to Microsoft's servers asking for a device code. Microsoft responds with a legitimate code — something like ABCD-1234. The attacker then sends you an email pretending to be Microsoft Teams, Adobe, DocuSign, SharePoint, or even a construction bid notification. The email says you need to verify your identity or access a shared document — and asks you to visit the real Microsoft login page at microsoft.com/devicelogin and enter the code provided.
You go to the real Microsoft website. You enter your actual Microsoft credentials. You complete your 2FA — your OTP arrives and you enter it. Microsoft verifies everything correctly, creates an access token and a refresh token, and hands them to whoever holds the device code.
That's the attacker. They now have your access token and refresh token — giving them full access to your Microsoft 365 account. Email, Teams messages, SharePoint files, OneDrive documents — everything. And here's the worst part: these tokens remain valid even if you change your password later. A password reset doesn't revoke the tokens the attacker already holds.
Why it's exploded in 2026 — phishing-as-a-service kits
Device code phishing isn't new — it was first documented in 2020 and has been used by state-sponsored hackers and financially motivated criminal groups since then. What's changed in 2026 is accessibility. A kit called EvilTokens emerged as a phishing-as-a-service (PhaaS) platform — meaning less technically skilled criminals can now run sophisticated device code phishing campaigns without understanding the underlying OAuth mechanics. They just subscribe to EvilTokens, pick a lure template, and run campaigns.
EvilTokens isn't alone. At least 11 different competing kits are now in circulation. VENOM offers device code phishing alongside adversary-in-the-middle capabilities. SHAREFILE uses document transfer themes to trick corporate employees into entering codes. CLURE uses SharePoint-themed lures with anti-bot protection and infrastructure hosted on DigitalOcean. LINKID uses Microsoft Teams and Adobe themes through Cloudflare pages. AUTHOV uses Adobe document-sharing lures. Each kit competes for the same criminal market, offering slightly different evasion techniques and lure templates.
The scale is already significant: one documented campaign targeted over 340 Microsoft 365 organisations across the United States, Canada, Australia, New Zealand, and Germany — using construction bid lures, DocuSign impersonation, voicemail notifications, and Microsoft Forms pages, all routing through the same Railway.com infrastructure. The campaign was first spotted on February 19, 2026, and cases have been appearing at accelerating pace since then.
Why Indian corporate users are particularly at risk
India has one of the largest Microsoft 365 user bases in the world. The platform is standard in IT services companies, BPO operations, financial services firms, healthcare providers, and government contractors. Infosys, Wipro, TCS, HCL, and thousands of smaller IT firms across Chennai, Bangalore, Hyderabad, and Pune run their entire internal communication and document infrastructure on Microsoft 365.
Device code phishing attacks don't require targeting India specifically — they target organisations with Microsoft 365 accounts globally, and India's corporate users are part of that global pool. A campaign using a DocuSign-themed lure or a "shared document" notification is convincing to anyone doing corporate work, regardless of geography. The financial stakes are high: a compromised Microsoft 365 account at an IT services company gives attackers access to client project data, internal HR information, financial documents, and email communication that can be used for business email compromise fraud — a scam that regularly results in fraudulent wire transfers of lakhs to crores of rupees.
For Indian startups using Microsoft Teams as their primary communication tool, a compromised account could expose investor communications, product roadmaps, customer data, and employment contracts. The DPDPA (Digital Personal Data Protection Act) creates regulatory liability for organisations that suffer data breaches — making a Teams or SharePoint compromise significantly more consequential than it might have been two years ago.
How to tell if you're being targeted — the warning signs
Device code phishing emails are convincing precisely because they direct you to real Microsoft pages. The attack doesn't involve a fake login page — that's what makes it so hard to catch. However, there are red flags to watch for.
The first red flag: you receive an unsolicited email asking you to enter a code at microsoft.com/devicelogin when you didn't initiate any login or device connection yourself. Legitimate device code prompts only appear when you're physically trying to connect a new device to your account — your TV, printer, or streaming device. If you get an email with a code and you're not connecting a device right now, treat it as an attack.
The second red flag: urgency language. "Your account will be suspended," "Document expires in 24 hours," "Verify immediately." These are classic social engineering pressure tactics designed to get you to act before you think.
The third red flag: the email domain doesn't match the service. A DocuSign notification should come from docusign.com, not docusign-notifications.net or similar lookalike domains.
What your IT team needs to do right now
For individuals, the defence is awareness — never enter a device code you didn't personally generate by connecting a device. For organisations, the technical responses are more specific. Microsoft allows administrators to disable the device code flow entirely for accounts that don't need it — most corporate employees never connect smart TVs or IoT devices to their Microsoft 365 accounts, so disabling this flow removes the attack surface completely. Conditional Access policies in Microsoft Entra ID (formerly Azure AD) can restrict which devices and locations are allowed to complete device code authentication. Monitoring for unusual token grants in the Microsoft Entra audit logs can detect successful attacks that got past user awareness.
The critical point about token revocation: changing your password is not enough if you've already completed a device code phishing attack. Your IT team needs to revoke the OAuth tokens directly through the Microsoft Entra admin portal — Settings, then Users, then the affected account's active sessions — to invalidate the attacker's access.
TamilTech's take
The 37x growth in device code phishing is a direct consequence of the phishing-as-a-service economy — where criminal infrastructure is productised and sold by subscription, lowering the technical barrier for running sophisticated attacks to near zero. EvilTokens and its competitors are effectively turning account takeover into a commodity service. For Indian corporate IT teams managing Microsoft 365 deployments, this is the security alert of Q1 2026. The attack defeats password security and 2FA simultaneously, targets real Microsoft infrastructure so URL-checking offers no protection, and leaves attackers with persistent access that survives a password reset. Review your Entra ID policies, disable device code flow for users who don't need it, and train your teams to never enter a device code they didn't personally generate.




Comments (0)
Be the first to comment!