How device code phishing gives scammers access to your account
Brief
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.
The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.
The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.
Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
How device code phishing gives scammers access to your account
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.
The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.
The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.
Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in.
This allows the app or device that displayed the code to access your account.
In this phishing attack, the scammer starts the sign-in and gets you to enter the code and approve the request. That can give the scammer access to your account.
How device code phishing works
Device code phishing relies on the OAuth 2.0 Device Authorization Grant , a standard sign-in method for devices with no browser or limited input.
An attack generally follows these steps:
- An attacker starts a legitimate device code sign-in request for an app or device they control.
- The sign-in service generates a short, temporary code and a legitimate verification page.
- The attacker uses social engineering , such as a fake Teams invite, a document-sharing request, or an invitation to join a “secure” chat, to pass that code to the victim.
- The victim visits the genuine sign-in page, enters the code, and approves the request.
- The attacker’s waiting device receives authentication tokens.
Those tokens act as digital passes, allowing the attacker to access the victim’s account without knowing their password.
How device code phishing gives scammers access to your account
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.
The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.
The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.
Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in.
This allows the app or device that displayed the code to access your account.
In this phishing attack, the scammer starts the sign-in and gets you to enter the code and approve the request. That can give the scammer access to your account.
How device code phishing works
Device code phishing relies on the OAuth 2.0 Device Authorization Grant , a standard sign-in method for devices with no browser or limited input.
An attack generally follows these steps:
- An attacker starts a legitimate device code sign-in request for an app or device they control.
- The sign-in service generates a short, temporary code and a legitimate verification page.
- The attacker uses social engineering , such as a fake Teams invite, a document-sharing request, or an invitation to join a “secure” chat, to pass that code to the victim.
