The authentication flow becomes the lure

Microsoft’s September 22 analysis of EvilTokens describes a phishing service that abuses device-code authentication to obtain tokens and compromise organizational accounts. The company reports more than 12,000 inboxes affected across over 10,000 organizations, figures that reflect its investigation rather than a census of all phishing. Microsoft also describes a coordinated disruption of infrastructure used by the service. Disruption of one service does not establish that this class of attack has ended.

Why the familiar warning is incomplete

Device-code phishing can involve a user authorizing a session through a legitimate authentication flow. Microsoft reports subsequent mailbox access and persistence, including malicious inbox rules in observed activity. Our analysis is that awareness material should explain the authorization decision, not rely exclusively on spotting an unusual website. Employees need a clear rule for unsolicited requests to enter a code or approve a login, along with an easy route to confirm whether a request was genuinely initiated by their organization.

Build the lesson around real work

For a university, an exercise might use a simulated invitation to review a shared document, with an agreed reporting route for students or staff. For a financial-services team, the exercise could focus on an unexpected document request connected to an ordinary business process. These are proposed training scenarios, not claims about particular victims. Use safe simulations that do not collect passwords or grant actual account access, and evaluate whether participants understand what they are being asked to authorize.

Give the help desk a complete escalation path

A report that a user approved an unexpected code should reach the identity and messaging teams promptly. We recommend documenting which team checks current sessions, mailbox changes and related access, and which person owns communication with the affected user. A password-reset ticket alone should not be treated as proof that every relevant access path has been examined. The strongest outcome of training is a fast, useful report that responders know how to act on, rather than an employee quietly hoping an unfamiliar prompt was harmless.

Sources & further reading

Our practical suggestions are editorial guidance. Verify applicability against current source and vendor instructions.

Suggest a correction →