CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker
The short version: In 2026, criminals began selling a ready-made phishing kit called EvilTokens that tricks employees into typing a code into a genuine Microsoft website. The employee signs in and approves MFA — and the attacker gets access. Microsoft reported hundreds of organizations being compromised per day at the campaign's peak.
Why this attack is so effective
- The website is real — it's Microsoft's own sign-in page.
- The employee does everything right — password, MFA approval.
- Traditional training ("check the URL") doesn't help.
- It's sold as a service, so even unskilled criminals can run campaigns.
The business impact
- Email takeover leading to invoice fraud.
- Data theft from mailboxes and files.
- Spread to partners through emails sent from trusted accounts.
The fix is mostly a setting
The sign-in method being abused — "device code" — is designed for TVs and printers. Most employees never need it. Turning it off for everyone except specific devices stops this attack.
Questions to ask your team
- Have we blocked device code sign-in for regular users?
- Who still needs it, and how are those exceptions controlled?
- Have employees been told never to enter a code someone sends them?
- Would we detect an account signing in this way?
What good looks like
Device code sign-in blocked by default, a small documented list of exceptions, user awareness, and monitoring for attempts.
The decision
Ask your team to confirm device code sign-in is blocked for general users. If it isn't, this is a same-week fix.
Sources
- EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365 Incident Teardowns
- How to Block Device Code Flow With Conditional Access How-To & Hardening
- Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries Detection & Response