Microsoft: Criminals can access your accounts without your password

Microsoft: Criminals can access your accounts without your password

Authors: Dot and Dash
July 7, 2025
TL;DR
Just when you think youโ€™ve got cyber security sorted for your business, a new scam comes along. This time, cyber criminals donโ€™t even need to trick you out of your password to access your accountsโ€ฆ they can fool you with something called a โ€œdevice codeโ€.

Have you ever felt like just when youโ€™ve nailed your cyber security โ€“ BAM! โ€“ something new comes along to throw a spanner in the works?

Thatโ€™s exactly whatโ€™s happening right now.

Thereโ€™s a new scam doing the rounds. And itโ€™s catching out businesses just like yours.

The worst part?

Cyber criminals donโ€™t even need your password.

Scaryโ€ฆ

Itโ€™s called device code phishing. Itโ€™s a clever trick thatโ€™s becoming more and more popular. Microsoft recently flagged a wave of these attacks, and weโ€™re likely to see many more.

This oneโ€™s different to the usual phishing scams youโ€™ve probably heard about. Normally, phishing is all about tricking people into giving away their usernames and passwords on fake websites.

But with device code phishing, scammers play a smarter game.

Instead of stealing your password, they get you to voluntarily give them access to your account. And they do it using real Microsoft login pages, so it looks totally legit.

It usually starts with a convincing email. Maybe it looks like itโ€™s from your HR person, or a colleague, inviting you to a Microsoft Teams meeting. You click the link, and it takes you to a real Microsoft login screen.

Nothing seems out of place.

Youโ€™re asked to enter a code. Just a short one, called a โ€œdevice code.โ€ This code is supplied in the email, and youโ€™re told itโ€™s needed to join the meeting or finish logging in.

Hereโ€™s the catch: By entering that code, youโ€™re not logging yourself inโ€ฆ youโ€™re logging them in.

Youโ€™re unknowingly giving the attacker access to your Microsoft account on their device. And because the login goes through the proper channels, it can even bypass multi-factor authentication (MFA).

Yep, even if youโ€™ve got extra security in place, they might still get in.

Once theyโ€™re in, they can do a lot of damage. Reading your emails, accessing your files, even using your account to trick others in your company. Itโ€™s like handing over the keys to your office and you donโ€™t even realise it.

Itโ€™s dangerous because it doesnโ€™t look suspicious. Youโ€™re on a real Microsoft site, not some suspicious fake. You didnโ€™t click a weird link or enter your password into a phishing form. Everything looks above boardโ€ฆ except itโ€™s not.

And because attackers are using legitimate Microsoft login flows, traditional security tools donโ€™t always catch it.

Plus, once theyโ€™re in, they can stay in. They donโ€™t need to keep logging in if theyโ€™ve captured your session token (thatโ€™s a sort of digital “pass” that keeps you logged in behind the scenes). So even changing your password wonโ€™t necessarily kick them out right away.

A big question then: How can you protect your business?

Start by getting your team to be extra cautious with login requests. Especially ones that involve entering codes. If you get a device code from someone, stop and think: Did I request this? Do I know for sure this is real?

If youโ€™re not sure, donโ€™t go through with it. Use a separate method, like a direct phone call or your companyโ€™s messaging system, to double-check with the person who sent the email.

Remember, real Microsoft logins donโ€™t involve someone else giving you a code to enter. If that ever happens, itโ€™s a red flag.

From a technical side, your IT team (or IT provider) can also tighten things up. If your business doesnโ€™t need device code login as part of its daily operations, itโ€™s safest to turn it off altogether. They can also put in place extra security rules that only allow logins from trusted locations or devices.

And finally, keep training your people. Good cyber security is about awareness. If your team knows what to look out for, theyโ€™re much less likely to fall for these kinds of tricks.

Can we help you tighten up your security? Get in touch.

Ready to stop thinking about IT?
We handle the complicated stuff so you can focus on what actually matters โ€“ running your business. Reach out and let’s see how we can help. Dot. Dash. Done.
Contact Us
Contact Us
Contact Us

Let's Chat

By submitting this form you give consent for Morse Networks to contact you about your enquiry. We will only use your data to respond to your query.

Let's Chat

By submitting this form you give consent for Morse Networks to contact you about your enquiry. We will only use your data to respond to your query.