Cyber Criminals Don’t Need Your Password Anymore

By: Ben Fielding | Estimated Reading Time: 3 minutes

Here’s How to Stop Them

“We’ve got MFA in place, we train our staff, we don’t click dodgy links. What more can we do?”

That’s the kind of question we hear from business owners all the time. And it’s a fair one. You’ve done the right things. But cyber threats don’t stand still, and the latest trick? It bypasses passwords entirely.

Yes, you read that right.

Introducing Device Code Phishing

Microsoft has raised the alarm about a sharp rise in something called device code phishing. It’s not your typical scam, and that’s exactly why it’s catching people out, even in well-protected businesses.

Here’s how it works:

  1. You receive what looks like a genuine email (maybe from a colleague, HR, or even Microsoft) inviting you to a Teams meeting.
  2. You’re taken to a real Microsoft login page. Nothing fake-looking.
  3. The email gives you a short device code to enter.
  4. You type it in, thinking you’re logging in.

But here’s the twist: you’re not logging in yourself – you’re logging in the attacker. On their device.

Because it’s going through legitimate Microsoft channels, even multi-factor authentication (MFA) might not stop it.

Once they’re in, they can:

  • Read your emails
  • Access your files and cloud apps
  • Impersonate you to other team members or clients

Worse still, they may not get kicked out even if you change your password. If they’ve captured your session token (your “stay logged in” pass), they can stay active in your account.

What You Can Do About It

Here are some straightforward, practical steps your business can take now to protect against device code phishing:


1. Raise Awareness Immediately

Make your team aware that real Microsoft login pages can be misused. Just because a login screen looks familiar doesn’t mean it’s safe.

Encourage your team to ask:

  • Did I request this login?
  • Why am I being asked to enter a device code?
  • Can I verify this with the sender, using a different method?

A good rule of thumb: always double-check using a known communication method, like a direct call or message. Never rely on replying to the original email.


2. Disable Device Code Authentication if It’s Not Needed

This feature is designed for specific login scenarios. If your business doesn’t rely on it, your IT provider can disable it entirely.

This removes the opportunity for attackers to exploit it.


3. Set Up Conditional Access Policies

Your Microsoft 365 environment can be configured to:

  • Only allow logins from trusted locations or company-managed devices
  • Detect and block high-risk login behaviour

This provides an extra layer of protection, even if an attacker has the right credentials.


4. Monitor for Unusual Activity

Session tokens can keep attackers logged in without needing a password. Your IT provider should monitor for:

  • Logins from unexpected countries or devices
  • New devices suddenly appearing
  • Suspicious changes like new inbox rules or permissions

These are often early signs that something is wrong.


5. Make Cyber Awareness Training Real-World and Ongoing

Include scenarios like device code phishing in your regular cyber training. The more familiar your staff are with current scams, the more confidently they can spot and stop them.

Training should be practical and relevant. Help people recognise unusual requests or login experiences, rather than just warning them about vague “cyber threats”.


Nxt Steps

Cyber criminals don’t need your password anymore, and that’s exactly why your defences need to go further than just MFA and antivirus.

At Nxt Gen IT, we help businesses stay ahead of the latest security threats with practical, layered protection, proactive monitoring, and real-world training that actually works.

If you’re unsure whether your Microsoft 365 setup is secure against modern phishing attacks like this, we’re here to help.

Get in touch today for a straightforward security review. No pressure, no jargon – just clear advice and a plan to keep your business protected.