
Phishing attacks are becoming much more difficult to recognize.
Instead of relying on poorly written emails and obvious fake login pages, cybercriminals are increasingly combining legitimate sign-in processes with automation and artificial intelligence to make their attacks appear more trustworthy.
One technique businesses should be aware of is device code phishing, an attack that can target Microsoft 365 users by taking advantage of a real authentication feature.
What makes this attack particularly convincing is that an employee may actually be sent to a legitimate Microsoft sign-in page. The website itself isn’t necessarily fake. The problem is the authentication request the employee has been tricked into approving.
Once that request is approved, an attacker may be able to obtain an authenticated session and gain access to the employee’s account.

How Does a Device Code Phishing Attack Work?
Device code authentication was created for legitimate purposes. It allows someone to sign into an account on a device where entering credentials directly may be inconvenient.
Cybercriminals can manipulate that process.
A typical attack can look something like this:
- The attacker starts a device authentication request.
- The legitimate authentication service creates a temporary device code.
- The attacker convinces an employee to use that code, often through a phishing email or convincing business-related message.
- The employee visits the legitimate sign-in service, enters the supplied code, and authenticates their account.
- The authentication service approves the request and issues an access token.
- Because the attacker initiated the request, they can obtain the token and potentially use it to access the employee’s account.
In other words, the employee isn’t necessarily typing their password into a fake website.
They can be completing a real authentication process for the wrong person.
Where Does AI Come Into the Attack?
AI makes campaigns like these concerning because cybercriminals can automate parts of the attack that previously required significantly more manual effort.
Generative AI can also help create phishing messages that are more believable and relevant to the recipient.
Instead of sending a generic message saying, “Your account has been suspended,” an attacker could create a message designed around the recipient’s job, company, or normal business activity.
A finance employee might receive something involving an invoice or payment request. Another employee might receive what appears to be a shared document, electronic signature request, or business notification.
The more closely the message resembles something the employee normally deals with, the less likely it is to immediately raise suspicion.
Why MFA Isn’t the Whole Solution
Multi-factor authentication is still one of the most important protections businesses can put in place.
However, attacks like device code phishing demonstrate why businesses shouldn’t rely on MFA alone.
In this scenario, the attacker may not need to defeat MFA through a technical exploit. Instead, the victim can unknowingly complete the authentication process themselves.
From the employee’s perspective, everything may appear normal. They reach Microsoft’s website, enter their credentials if requested, complete MFA, and continue.
The issue is that they have authenticated a request initiated by an attacker.
That’s an important distinction for businesses because cybersecurity awareness has traditionally taught employees to look for fake URLs and suspicious login pages.
Those warning signs aren’t always going to be there.
What Could an Attacker Do With the Account?
Access to a Microsoft 365 account can provide cybercriminals with much more than an employee’s inbox.
Depending on the account and its permissions, an attacker may be able to review email conversations, search for sensitive information, identify customers or vendors, learn how the organization operates, or use the compromised identity to target other people.
Financially sensitive accounts can be especially valuable.
For example, access to someone’s mailbox could allow an attacker to study existing conversations involving invoices or payments. That information could then potentially be used in a highly convincing business email compromise attempt.
A compromised account can also make the attack appear more legitimate to the next victim because malicious messages may now come from an email address they already recognize and trust.
The Bigger Cybersecurity Problem
Device code phishing highlights an important change happening in cybersecurity.
Attackers don’t always need to break through security controls.
Sometimes it’s easier to convince an authorized employee to open the door for them.
And as AI improves the quality and scale of social engineering campaigns, businesses need to prepare employees for attacks that may look significantly more professional than the phishing emails they’re used to seeing.
Cybersecurity protections should therefore extend beyond antivirus and passwords.
Organizations should evaluate identity security, email protection, conditional access policies, employee cybersecurity training, endpoint protection, account monitoring, and the authentication methods allowed within their environment.
If device code authentication isn’t necessary for an organization, administrators should also evaluate whether it can be restricted through their identity and access policies.
Protecting Your Business From Modern Phishing Attacks
Phishing isn’t going away. It’s evolving.
AI, automation, legitimate cloud services, and increasingly sophisticated social engineering techniques are giving attackers new ways to make malicious activity look normal.
Businesses should regularly review how employees authenticate, what happens when unusual account activity occurs, and whether someone is actively monitoring for signs of compromise.
Devfuzion provides 24/7 IT support and managed cybersecurity services to help businesses strengthen their defenses against phishing, account compromise, and other modern cyber threats.
From employee cybersecurity training and email security to identity protection, endpoint security, monitoring, and incident response, a layered security strategy can make it significantly harder for one successful phishing attempt to become a larger security incident.
Concerned about your organization’s Microsoft 365 security or phishing protection? Contact Devfuzion to learn how we can help strengthen your cybersecurity.