Have you ever felt like just when youโve nailed your cyber security โ BAM! โ something new comes along to throw a spanner in the works?
Thatโs exactly whatโs happening right now.
Thereโs a new scam doing the rounds. And itโs catching out businesses just like yours.
The worst part?
Cyber criminals donโt even need your password.
Scaryโฆ
Itโs called device code phishing. Itโs a clever trick thatโs becoming more and more popular. Microsoft recently flagged a wave of these attacks, and weโre likely to see many more.
This oneโs different to the usual phishing scams youโve probably heard about. Normally, phishing is all about tricking people into giving away their usernames and passwords on fake websites.
But with device code phishing, scammers play a smarter game.
Instead of stealing your password, they get you to voluntarily give them access to your account. And they do it using real Microsoft login pages, so it looks totally legit.
It usually starts with a convincing email. Maybe it looks like itโs from your HR person, or a colleague, inviting you to a Microsoft Teams meeting. You click the link, and it takes you to a real Microsoft login screen.
Nothing seems out of place.
Youโre asked to enter a code. Just a short one, called a โdevice code.โ This code is supplied in the email, and youโre told itโs needed to join the meeting or finish logging in.
Hereโs the catch: By entering that code, youโre not logging yourself inโฆ youโre logging them in.
Youโre unknowingly giving the attacker access to your Microsoft account on their device. And because the login goes through the proper channels, it can even bypass multi-factor authentication (MFA).
Yep, even if youโve got extra security in place, they might still get in.
Once theyโre in, they can do a lot of damage. Reading your emails, accessing your files, even using your account to trick others in your company. Itโs like handing over the keys to your office and you donโt even realise it.
Itโs dangerous because it doesnโt look suspicious. Youโre on a real Microsoft site, not some suspicious fake. You didnโt click a weird link or enter your password into a phishing form. Everything looks above boardโฆ except itโs not.
And because attackers are using legitimate Microsoft login flows, traditional security tools donโt always catch it.
Plus, once theyโre in, they can stay in. They donโt need to keep logging in if theyโve captured your session token (thatโs a sort of digital “pass” that keeps you logged in behind the scenes). So even changing your password wonโt necessarily kick them out right away.
A big question then: How can you protect your business?
Start by getting your team to be extra cautious with login requests. Especially ones that involve entering codes. If you get a device code from someone, stop and think: Did I request this? Do I know for sure this is real?
If youโre not sure, donโt go through with it. Use a separate method, like a direct phone call or your companyโs messaging system, to double-check with the person who sent the email.
Remember, real Microsoft logins donโt involve someone else giving you a code to enter. If that ever happens, itโs a red flag.
From a technical side, your IT team (or IT provider) can also tighten things up. If your business doesnโt need device code login as part of its daily operations, itโs safest to turn it off altogether. They can also put in place extra security rules that only allow logins from trusted locations or devices.
And finally, keep training your people. Good cyber security is about awareness. If your team knows what to look out for, theyโre much less likely to fall for these kinds of tricks.
Can we help you tighten up your security? Get in touch.