Executive Summary
In early 2026, a sophisticated phishing campaign exploited Microsoft's OAuth 2.0 Device Authorization Grant flow to compromise user accounts. Attackers initiated the device code authentication process and tricked victims into entering the provided code on Microsoft's legitimate login page, thereby granting unauthorized access without exposing credentials. This method allowed threat actors to bypass multi-factor authentication (MFA) and maintain persistent access to services like Outlook, OneDrive, and Teams by capturing access and refresh tokens. The campaign, active from April to mid-May 2026, targeted Microsoft 365 users through deceptive emails and malicious attachments, leading to significant data breaches and unauthorized account activities.
The incident underscores a growing trend of attackers leveraging legitimate authentication mechanisms to bypass traditional security measures. The rise of device code phishing highlights the need for organizations to reassess their security protocols, especially concerning OAuth flows and MFA implementations. As phishing techniques become more sophisticated, continuous monitoring, user education, and the implementation of conditional access policies are crucial to mitigate such threats.
Why This Matters Now
The surge in device code phishing attacks exploiting legitimate authentication flows poses an immediate threat to organizational security, emphasizing the urgency for enhanced monitoring and policy enforcement.
Attack Path Analysis
Attackers initiated the campaign by sending phishing emails with password-protected PDFs, leading victims to a malicious link that redirected through a legitimate Microsoft URL to a phishing page. Upon entering the provided one-time code on the official Microsoft authentication page, victims unknowingly granted attackers access tokens, enabling unauthorized access to their emails, OneDrive files, and Teams conversations. The attackers maintained persistent access by utilizing the obtained refresh tokens to renew access tokens without further user interaction.
Kill Chain Progression
Initial Compromise
Description
Attackers sent phishing emails containing password-protected PDFs that, when opened, directed victims to a malicious link disguised as a legitimate Microsoft URL.
MITRE ATT&CK® Techniques
Spearphishing Link
Valid Accounts: Cloud Accounts
Use Alternate Authentication Material: Application Access Token
Application Layer Protocol: Web Protocols
Email Collection: Remote Email Collection
Data from Cloud Storage
Application Layer Protocol: Mail Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and software vulnerabilities are defined, documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA Zero Trust Maturity Model 2.0 – Implement strong authentication mechanisms
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Device Code Phishing attacks targeting Microsoft OAuth bypass traditional URL verification, enabling unauthorized access to financial data through legitimate authentication portals.
Legal Services
Law firm-themed phishing campaigns exploit Device Authorization Grant flows to access confidential client communications, case files, and privileged attorney-client information.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations when attackers use legitimate Microsoft authentication to access patient records and medical communications systems.
Information Technology/IT
IT sectors managing multi-tenant environments are vulnerable to Device Code abuse, requiring enhanced monitoring and conditional access policies for OAuth flows.
Sources
- When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft websitehttps://securelist.com/microsoft-device-code-phishing-attack/120350/Verified
- Inside an AI‑enabled device code phishing campaignhttps://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/Verified
- Storm-2372 conducts device code phishing campaignhttps://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it may have limited the attacker's ability to exploit compromised credentials by enforcing strict segmentation and identity-aware access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely have limited the attacker's ability to escalate privileges by enforcing strict access controls and segmenting network traffic based on identity.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely have constrained the attacker's lateral movement by enforcing strict segmentation and monitoring east-west traffic within the network.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely have limited the attacker's ability to maintain control by providing comprehensive monitoring and control over network traffic across multiple cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely have constrained data exfiltration by enforcing strict egress policies and monitoring outbound traffic.
While Aviatrix CNSF cannot entirely prevent the initial compromise, its enforcement of strict segmentation and access controls would likely have reduced the overall impact by limiting the attacker's reach and ability to exfiltrate data.
Impact at a Glance
Affected Business Functions
- Email Communications
- File Storage and Sharing
- Collaboration Platforms
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive emails, files, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access and limit lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Deploy Threat Detection & Anomaly Response systems to identify and mitigate phishing attempts and unauthorized access.
- • Educate users on recognizing phishing attempts and the importance of verifying authentication requests, even on legitimate platforms.



