How device code phishing gives scammers access to your account
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared doc 2026-9-23 18:59:38 Author: www.malwarebytes.com(查看原文) 阅读量:8 收藏

You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.

The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.

The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.

Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in. This allows the app or device that displayed the code to access your account.

In this phishing attack, the scammer starts the sign-in and gets you to enter the code and approve the request. That can give the scammer access to your account.

How device code phishing works

Device code phishing relies on the OAuth 2.0 Device Authorization Grant, a standard sign-in method for devices with no browser or limited input.

An attack generally follows these steps:

  1. An attacker starts a legitimate device code sign-in request for an app or device they control.
  2. The sign-in service generates a short, temporary code and a legitimate verification page.
  3. The attacker uses social engineering, such as a fake Teams invite, a document-sharing request, or an invitation to join a “secure” chat, to pass that code to the victim.
  4. The victim visits the genuine sign-in page, enters the code, and approves the request.
  5. The attacker’s waiting device receives authentication tokens.

Those tokens act as digital passes, allowing the attacker to access the victim’s account without knowing their password.

What the attacker can access depends on the app and the permissions granted. It could be limited to one service, or include email, files, contacts, and other services. Multifactor authentication (MFA) doesn’t necessarily stop this attack, because the victim may complete the MFA check themselves while authorizing the attacker’s sign-in.

Checking the address alone will not reveal this as a scam because it’s a legitimate page. For example, in an attack targeting a Microsoft account the victim may be sent to a genuine Microsoft sign-in page, such as microsoft.com/devicelogin. Some approval screens identify the app requesting access, but others may not.

The key question to ask yourself here is: Did this code appear in an app or on a device I was trying to sign in to, or was I given it to open a document, join a meeting, or pass a security check?

How to stay safe

Device code phishing is a feature of phishing kits such as EvilTokens. Be cautious if an unexpected message asks you to:

  • Enter a code on an account sign-in page.
  • Approve a sign-in for a device or application you did not set up.
  • Use a sign-in code to join a meeting, access a document, or enter a chatroom.
  • Act urgently because an invitation, document, password, or account supposedly expires soon.
  • Move a conversation to another messaging app and complete a “security check.”

If you entered the code and approved the sign-in, check the account’s recent activity, connected apps, and devices for anything you don’t recognize. Sign out everywhere and change your password.

Pro tip: Use the free Malwarebytes Scam Guard to help you assess a suspicious message and decide what to do next.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/how-to/2026/09/how-device-code-phishing-gives-scammers-access-to-your-account
如有侵权请联系:admin#unsafe.sh