Executive Summary
In August 2026, the 'Greatness' phishing-as-a-service (PhaaS) platform introduced device code phishing capabilities, enabling attackers to bypass multi-factor authentication (MFA) and gain unauthorized access to Microsoft 365 accounts. This method exploits the OAuth 2.0 Device Authorization Grant, tricking users into authenticating a malicious device by entering a provided code on a legitimate Microsoft page. Once the code is entered, attackers obtain access and refresh tokens, allowing persistent access to services like Outlook, Teams, and OneDrive without needing user credentials. This development signifies a significant evolution in phishing tactics, as it leverages legitimate authentication flows to circumvent traditional security measures. The commoditization of such advanced techniques through PhaaS platforms like 'Greatness' lowers the barrier for cybercriminals, increasing the prevalence and sophistication of phishing attacks targeting organizations and individuals alike.
Why This Matters Now
The emergence of device code phishing in PhaaS platforms like 'Greatness' highlights a critical vulnerability in current MFA implementations. Organizations must reassess their authentication strategies and implement additional safeguards to protect against these evolving threats.
Attack Path Analysis
The Greatness PhaaS toolkit initiates attacks by sending phishing emails containing malicious links to users. Upon clicking, victims are redirected to a fake login page that mimics legitimate services, where they are prompted to enter their credentials. The toolkit then exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA), allowing attackers to obtain OAuth tokens. With these tokens, attackers gain unauthorized access to the victim's cloud services, enabling them to move laterally within the environment. Subsequently, the attackers establish command and control channels to maintain persistent access. They exfiltrate sensitive data from the compromised accounts. Finally, the attackers may disrupt services or deploy ransomware to achieve their objectives.
Kill Chain Progression
Initial Compromise
Description
Attackers send phishing emails containing malicious links to users, leading them to counterfeit login pages.
MITRE ATT&CK® Techniques
Phishing
Multi-Factor Authentication Request Generation
Multi-Factor Authentication Interception
Modify Authentication Process: Multi-Factor Authentication
Adversary-in-the-Middle
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Multi-Factor Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Device code phishing bypasses MFA protections critical for financial authentication, enabling OAuth token theft and unauthorized access to customer accounts and sensitive financial data.
Health Care / Life Sciences
Greatness PhaaS threatens HIPAA compliance through MFA bypass attacks, potentially compromising patient data systems and medical records requiring zero trust segmentation protections.
Information Technology/IT
IT infrastructure faces elevated risk from adversary-in-the-middle credential harvesting, requiring enhanced egress security and anomaly detection to prevent lateral movement attacks.
Government Administration
OAuth device code exploitation threatens government systems security, necessitating strengthened multi-factor authentication and zero trust network controls for sensitive administrative operations.
Sources
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokenshttps://thehackernews.com/2026/08/greatness-phaas-adds-device-code.htmlVerified
- FBI warns about PhaaS platform used to access Microsoft 365 environmentshttps://www.cybersecuritydive.com/news/fbi-warns-phishing-platform-microsoft-365/821105/Verified
- Device Code Phishing Exploiting OAuth 2.0 Device Authorization Grant Flowhttps://feed.craftedsignal.io/briefs/2026-05-device-code-phishing/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can significantly limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, its integration with identity-aware policies could potentially limit the effectiveness of credential-based attacks by enforcing strict access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix's Zero Trust Segmentation would likely constrain the attacker's ability to escalate privileges by enforcing strict, identity-based access controls that limit access to sensitive resources.
Control: East-West Traffic Security
Mitigation: Aviatrix's East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring of internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix's Multicloud Visibility & Control would likely constrain the attacker's ability to maintain command and control by providing comprehensive monitoring and control over cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix's Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by controlling and monitoring outbound traffic.
While Aviatrix CNSF focuses on limiting attacker movement and data exfiltration, its comprehensive security controls may reduce the overall impact of such attacks by containing them within segmented environments.
Impact at a Glance
Affected Business Functions
- Email Communications
- Cloud Storage Access
- Collaboration Platforms
- Identity and Access Management
Estimated downtime: 7 days
Estimated loss: $500,000
Unauthorized access to sensitive corporate emails, confidential documents stored in cloud services, and potential compromise of collaboration tools.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access based on identity and context, limiting lateral movement.
- • Enhance Multi-Factor Authentication mechanisms to detect and prevent unauthorized access attempts.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Conduct regular security awareness training to educate users on recognizing and reporting phishing attempts.



