Security researchers and Microsoft itself have confirmed that hundreds of Microsoft 365 accounts are being compromised every day through a technique called device code phishing. More than 340 organisations across multiple countries have already been hit, and turnkey phishing kits are now being sold as a service, which means the volume of attacks is rising fast. If your business runs on Microsoft 365 — and most UK SMEs do — this is worth five minutes of your attention today.
How the attack actually works
Device code phishing abuses a genuine Microsoft sign-in feature designed for devices with no keyboard, such as smart TVs or some meeting room hardware. Normally, you’d see a short code and a prompt to enter it on a separate device to sign in.
Attackers exploit this by sending an email or Teams message — often disguised as a meeting invite, a document share, or an internal IT notice — that asks the recipient to visit Microsoft’s real, legitimate login page and enter a code. Because the page genuinely belongs to Microsoft, it passes every visual and technical check an employee might think to make. There’s no fake domain, no obvious spelling error.
Once the code is entered, the attacker silently receives a valid access token for that person’s account, with no password and no second login prompt needed afterwards. From there, criminals can read email, set up forwarding rules to siphon out invoices or client data, search for sensitive files, and use the compromised account to send further phishing messages to colleagues and clients who will trust the sender.
Why this slips past normal defences
Multi-factor authentication, which most businesses now rely on as their main defence against phishing, does not stop this attack. The victim isn’t entering a stolen password on a fake site — they’re completing a real Microsoft authentication flow on Microsoft’s own domain. Standard staff training that focuses on “check the URL” and “look for spelling mistakes” misses this entirely, because there’s nothing to spot.
Construction, professional services, and finance firms have been disproportionately targeted, largely because they handle high volumes of email-based requests and approvals — exactly the SME profile common across the UK.
What to do this week
Brief your team specifically on this trick. Make sure everyone understands that being asked to enter a “device code” on a Microsoft login page, especially via an unexpected Teams message or email, is a red flag — not a normal IT request.
Restrict or disable the device code sign-in flow if your business doesn’t genuinely need it. Microsoft 365 admins can use Conditional Access policies to block or tightly restrict this authentication method. If you don’t manage this in-house, ask your IT provider to do it this week — it’s a quick change with low disruption for most SMEs.
Monitor for unusual sign-in activity. New mail forwarding rules, logins from unfamiliar locations, or new app registrations are common signs of a compromised account. Services like KeepSafe continuously monitor for exactly these signals, flagging suspicious account activity before it turns into a full breach or a client-facing incident.
Review who actually has admin rights. A compromised account with limited permissions is a contained problem. A compromised admin account is a much bigger one. Cut down standing admin access wherever you reasonably can.
The takeaway
Device code phishing works precisely because it doesn’t look like phishing. The fix isn’t more suspicion of dodgy links — it’s making sure your team and your Microsoft 365 configuration are ready for an attack that looks completely legitimate. A short policy change and a five-minute team briefing this week could be what stands between you and an account takeover next month.