12,000 Inboxes Were Compromised Without Stealing a Password. The Victims Logged In on the Real Login Page
The website was real. The password wasn't stolen. Multi-factor authentication worked exactly as designed. And the attacker still got in. This week, Microsoft disclosed and dismantled an AI-powered phishing operation that used exactly this technique to compromise more than 12,000 inboxes at over 10,000 organizations worldwide, since February. Here's how a real login page became part of the attack, and the one rule that stops it.
For years, the first thing anyone learns about phishing is to check the address bar. Is this the real site? Is the certificate valid? Does the domain match? That instinct is correct, and it stops an enormous share of ordinary phishing. It's also, on its own, no longer a complete defense — because the technique behind this week's news doesn't need a fake website at all.
How a real login page becomes part of the attack
The technique is called device code phishing, and it abuses a legitimate feature built to make signing in easier on devices without a keyboard, like a smart TV or a conference-room system. Normally, that device displays a short code, and you enter the code on a second device, like your phone, at the real sign-in page, to link the two.
Attackers found a way to weaponize that convenience. The victim receives something that looks like an ordinary business message, an invoice, a shared file, a password-expiration notice, containing a device code and a link to the genuine login page. The victim enters the code where they're told to, and if prompted, completes their own real password and their own real MFA. Everything about the process, from the attacker's perspective, has just worked exactly as intended — except the code the victim entered belongs to the attacker's session, not their own. The authorization server, satisfied that a legitimate login just occurred, issues valid access tokens directly to the attacker's device. The victim effectively authenticates the attacker, using their own credentials, without ever handing those credentials over.
The phishing page doesn't always have to be fake anymore. Sometimes the attacker just needs to trick you into authenticating the wrong session on the real one.
inboxes compromised across more than 10,000 organizations worldwide, since the service emerged in February
Microsoft's Digital Crimes Unit disclosed this week that it had tracked, and this week dismantled, a phishing-as-a-service operation built around exactly this technique. Victims were concentrated in the US, Canada, the UK, Australia, India, and France, spanning wholesale distribution, construction, financial services, real estate, higher education, and healthcare — ordinary businesses across ordinary industries, not a narrow slice of large technology companies.
The AI twist: it's not just writing better emails anymore
What made this particular operation notable wasn't only its scale. Microsoft said the service used AI at multiple points in the attack chain, and not only to make the initial lure more convincing.
That's a meaningful shift from what most AI-phishing coverage has focused on this year. The earlier story was that AI helps criminals write more convincing emails. This is AI helping decide what's worth stealing, and from whom, after the door is already open — turning a successful phishing click into an automatically prioritized target list rather than a single compromised mailbox.
The part of this story that's actually good news
Unlike most of what this series covers, this isn't only a warning. It's also a genuine success story worth sitting with for a moment. Microsoft, working with a coalition of outside cybersecurity and threat-intelligence partners, tracked this operation, obtained federal court authorization, and seized 50 websites along with more than 150 additional domains tied to the service. UK police separately arrested two men, ages 32 and 38, in connection with running its technical infrastructure — both released on bail while the investigation continues, and neither yet convicted of anything.
The SMB translation
"This is the real website" has been the single most repeated piece of security advice for two decades. It's still correct advice. It's no longer sufficient advice, because this technique proves the legitimate site itself can be part of the attack flow, not a signal that you're safe from one.
Microsoft's own stated recommendation is more direct still: for most organizations, the device code authentication flow should simply be blocked via Conditional Access where it isn't specifically needed. It's the same core fix we've recommended before, for an earlier and smaller device-code phishing kit covered on this blog. This week's news is evidence of how far that same basic technique has scaled since then, not a reason to think the fix has changed.
The short version
Twelve thousand inboxes, ten thousand organizations, a real login page every single time. The lesson isn't that Microsoft's sign-in process is broken; it's that a legitimate feature can be turned into an attack when a victim is convinced to hand over a code they never should have entered. Checking the address bar still matters. It's no longer the whole test. The new question, for any device code you're asked to enter, is simple: did I ask for this, or did someone just ask me to authorize them?
Find out whether this exact exposure exists in your environment today.
View the Threat Intelligence feed → Find Out More About ThreatAngel →📚 Credential Security Series → Read the full series

Comments
Post a Comment