12,000 Inboxes Were Compromised Without Stealing a Password. The Victims Logged In on the Real Login Page



Takedown
Good News, Real Lesson
September 2026  ·  8 min read

The website was real. The password wasn't stolen. Multi-factor authentication worked exactly as designed. And the attacker still got in. This week, Microsoft disclosed and dismantled an AI-powered phishing operation that used exactly this technique to compromise more than 12,000 inboxes at over 10,000 organizations worldwide, since February. Here's how a real login page became part of the attack, and the one rule that stops it.


For years, the first thing anyone learns about phishing is to check the address bar. Is this the real site? Is the certificate valid? Does the domain match? That instinct is correct, and it stops an enormous share of ordinary phishing. It's also, on its own, no longer a complete defense — because the technique behind this week's news doesn't need a fake website at all.

✓The login page was genuine — the real Microsoft sign-in, not a lookalike.
✓The victim's own password was never stolen or exposed at any point.
✓Multi-factor authentication completed successfully, exactly as designed.
✗The attacker still ended up with ongoing access to the account.

How a real login page becomes part of the attack

The technique is called device code phishing, and it abuses a legitimate feature built to make signing in easier on devices without a keyboard, like a smart TV or a conference-room system. Normally, that device displays a short code, and you enter the code on a second device, like your phone, at the real sign-in page, to link the two.

Attackers found a way to weaponize that convenience. The victim receives something that looks like an ordinary business message, an invoice, a shared file, a password-expiration notice, containing a device code and a link to the genuine login page. The victim enters the code where they're told to, and if prompted, completes their own real password and their own real MFA. Everything about the process, from the attacker's perspective, has just worked exactly as intended — except the code the victim entered belongs to the attacker's session, not their own. The authorization server, satisfied that a legitimate login just occurred, issues valid access tokens directly to the attacker's device. The victim effectively authenticates the attacker, using their own credentials, without ever handing those credentials over.

The phishing page doesn't always have to be fake anymore. Sometimes the attacker just needs to trick you into authenticating the wrong session on the real one.

12,000+

inboxes compromised across more than 10,000 organizations worldwide, since the service emerged in February

Microsoft's Digital Crimes Unit disclosed this week that it had tracked, and this week dismantled, a phishing-as-a-service operation built around exactly this technique. Victims were concentrated in the US, Canada, the UK, Australia, India, and France, spanning wholesale distribution, construction, financial services, real estate, higher education, and healthcare — ordinary businesses across ordinary industries, not a narrow slice of large technology companies.

The AI twist: it's not just writing better emails anymore

What made this particular operation notable wasn't only its scale. Microsoft said the service used AI at multiple points in the attack chain, and not only to make the initial lure more convincing.

What the AI reportedly did after the phishing succeeded
Tailored each phishing message specifically to the victim's role at their organization
Analyzed newly compromised inboxes to identify high-value finance, executive, and administrative targets
Mapped trusted relationships between the victim, their executives, and outside organizations
Searched compromised mailboxes for wire-transfer details, pending invoices, and executive correspondence to inform what came next

That's a meaningful shift from what most AI-phishing coverage has focused on this year. The earlier story was that AI helps criminals write more convincing emails. This is AI helping decide what's worth stealing, and from whom, after the door is already open — turning a successful phishing click into an automatically prioritized target list rather than a single compromised mailbox.

The part of this story that's actually good news

Unlike most of what this series covers, this isn't only a warning. It's also a genuine success story worth sitting with for a moment. Microsoft, working with a coalition of outside cybersecurity and threat-intelligence partners, tracked this operation, obtained federal court authorization, and seized 50 websites along with more than 150 additional domains tied to the service. UK police separately arrested two men, ages 32 and 38, in connection with running its technical infrastructure — both released on bail while the investigation continues, and neither yet convicted of anything.

Real defenses, real coordination across companies and governments, and a real disruption of a criminal operation at scale. That's worth acknowledging directly: this technique did enormous damage, and it was also detected, tracked, and dismantled. Both things are true, and the second one is the reason this story exists to be told at all.

The SMB translation

"This is the real website" has been the single most repeated piece of security advice for two decades. It's still correct advice. It's no longer sufficient advice, because this technique proves the legitimate site itself can be part of the attack flow, not a signal that you're safe from one.

The one new rule worth adding to your team's training today: never enter a device code because an email, a document, a recruiter, a vendor, a help-desk message, or an unexpected webpage told you to. A device code you didn't personally request, from a sign-in you didn't personally initiate, is someone else trying to borrow your identity, even when the page asking for it is completely real.

Microsoft's own stated recommendation is more direct still: for most organizations, the device code authentication flow should simply be blocked via Conditional Access where it isn't specifically needed. It's the same core fix we've recommended before, for an earlier and smaller device-code phishing kit covered on this blog. This week's news is evidence of how far that same basic technique has scaled since then, not a reason to think the fix has changed.

This also connects directly to our recent piece on why a stolen password reset and an MFA reset don't always close every open session. That post explained why a stolen token can outlive the credential that produced it. This story shows exactly how attackers are getting people to hand over that token in the first place, using a process that looks, at every visible step, completely normal.
This is precisely the identity and access risk the ThreatAngel CyberScore's Security Posture assessment is built to help surface, and it's the kind of active threat our Threat Intelligence feed exists to flag while it's still relevant, not months after the fact. Knowing whether device code authentication is restricted in your environment, and whether your team knows the one rule above, is a five-minute conversation with real consequences either way.

The short version

Twelve thousand inboxes, ten thousand organizations, a real login page every single time. The lesson isn't that Microsoft's sign-in process is broken; it's that a legitimate feature can be turned into an attack when a victim is convinced to hand over a code they never should have entered. Checking the address bar still matters. It's no longer the whole test. The new question, for any device code you're asked to enter, is simple: did I ask for this, or did someone just ask me to authorize them?

Find out whether this exact exposure exists in your environment today.

View the Threat Intelligence feed → Find Out More About ThreatAngel →
TA
ThreatAngel Team AI-powered cyber risk clarity for SMBs  ·  threatangel.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.