M365 phishing is now riding device codes — and your phone is the key
Microsoft 365 has a less-talked-about auth path called the device code flow. You open a URL on a browser, it shows a code, then you punch that code into the Microsoft Authenticator app on your phone. The app talks directly to Microsoft and hands back an access token. No browser cookies, no redirect loops. It's how you sign in from a headless machine.
The phishers figured this out. Instead of the usual fake login page that asks for your password, they now point you at a Microsoft-hosted URL that looks identical to the real one. You scan the code with Authenticator — the app trusts Microsoft, so it grants the token — and suddenly the attacker has a valid session. No password, no MFA prompt. The token lives on for hours, long enough to walk through your OneDrive, steal emails, and leave before you notice.
The difference is subtle but important. Old M365 phishing tricks you into typing your credentials into a copycat page. This version tricks you into approving the login on your phone. You think you're just saying yes to a new device. You're actually opening a back door.
Why this matters for us: la gente que confía en su celular para abrir la puerta de su trabajo está dejando la llave en la manilla — el token en tu teléfono es ahora una puerta trasera que no pediste.
“You're not just approving a new device — you're leaving the key on the door.”