Article
Aug 16, 2026
Anatomy of a Device Code Phishing Email: A Real Investigation
A phishing email with no malware, no cloned login page and a clean URL reputation would still have handed an attacker a fully authenticated Microsoft 365 session — without ever seeing the password, and without the victim's MFA slowing them down. This is a captured, screen-by-screen walkthrough of a device code phishing email (the Cloudflare hold-to-continue gate, the copied Microsoft device code, the genuine sign-in page) plus the detection, hardening, and full mitigating and compensating controls to stop it.