Microsoft 365CIO BriefingsNews

CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine Microsoft website. The employee signs in and approves MFA — and the attacker gets access. Microsoft reported hundreds of organizations being compromised per day at the campaign's peak.

Why this attack is so effective

  • The website is real — it's Microsoft's own sign-in page.
  • The employee does everything right — password, MFA approval.
  • Traditional training ("check the URL") doesn't help.
  • It's sold as a service, so even unskilled criminals can run campaigns.

The business impact

  • Email takeover leading to invoice fraud.
  • Data theft from mailboxes and files.
  • Spread to partners through emails sent from trusted accounts.

The fix is mostly a setting

The sign-in method being abused — "device code" — is designed for TVs and printers. Most employees never need it. Turning it off for everyone except specific devices stops this attack.

Questions to ask your team

  • Have we blocked device code sign-in for regular users?
  • Who still needs it, and how are those exceptions controlled?
  • Have employees been told never to enter a code someone sends them?
  • Would we detect an account signing in this way?

What good looks like

Device code sign-in blocked by default, a small documented list of exceptions, user awareness, and monitoring for attempts.

The decision

Ask your team to confirm device code sign-in is blocked for general users. If it isn't, this is a same-week fix.

Sources

  1. Source
eviltokens device code phishing impactEvilTokens device code phishing2026

More on this story