Skip to content

Topic

Device Code Phishing

A phishing technique abusing OAuth device-authorization flows, tricking victims into entering an attacker's code to steal valid login tokens.

Current stories

security6 publishers

Storm-3121 callers demand an urgent passkey update to harvest Microsoft 365 session tokens

Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence58
Adoption
Insufficient
Hype gap+10
Incentives45
Confidence60
security8 publishers

EvilTokens rented an AI-powered inbox-scanning tool and a device-code MFA bypass for a $1,500 fee plus $500 a month

Microsoft's Digital Crimes Unit and its partners pulled down the EvilTokens phishing service about seven months after it launched, and British police arrested its two suspected operators. The authentication technique it sold survives on other platforms.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 60%
Investor
Investor 15%

Reality

Evidence66
Adoption58
Hype gap+18
Incentives62
Confidence64