Home 9 Latest News 9 Microsoft: Criminals can access your accounts without your password

Microsoft: Criminals can access your accounts without your password

Have you ever felt like just when you’ve nailed your cyber security – BAM! – something new comes along to throw a spanner in the works?

That’s exactly what’s happening right now.

There’s a new scam doing the rounds. And it’s catching out businesses just like yours.

The worst part?

Cyber criminals don’t even need your password.

Scary…

It’s called device code phishing. It’s a clever trick that’s becoming more and more popular. Microsoft recently flagged a wave of these attacks, and we’re likely to see many more.

This one’s different to the usual phishing scams you’ve probably heard about. Normally, phishing is all about tricking people into giving away their usernames and passwords on fake websites.

But with device code phishing, scammers play a smarter game.

Instead of stealing your password, they get you to voluntarily give them access to your account. And they do it using real Microsoft login pages, so it looks totally legit.

It usually starts with a convincing email. Maybe it looks like it’s from your HR person, or a colleague, inviting you to a Microsoft Teams meeting. You click the link, and it takes you to a real Microsoft login screen.

Nothing seems out of place.

You’re asked to enter a code. Just a short one, called a “device code.” This code is supplied in the email, and you’re told it’s needed to join the meeting or finish logging in.

Here’s the catch: By entering that code, you’re not logging yourself in… you’re logging them in.

You’re unknowingly giving the attacker access to your Microsoft account on their device. And because the login goes through the proper channels, it can even bypass multi-factor authentication (MFA).

Yep, even if you’ve got extra security in place, they might still get in.

Once they’re in, they can do a lot of damage. Reading your emails, accessing your files, even using your account to trick others in your company. It’s like handing over the keys to your office and you don’t even realise it.

It’s dangerous because it doesn’t look suspicious. You’re on a real Microsoft site, not some suspicious fake. You didn’t click a weird link or enter your password into a phishing form. Everything looks above board… except it’s not.

And because attackers are using legitimate Microsoft login flows, traditional security tools don’t always catch it.

Plus, once they’re in, they can stay in. They don’t need to keep logging in if they’ve captured your session token (that’s a sort of digital “pass” that keeps you logged in behind the scenes). So even changing your password won’t necessarily kick them out right away.

A big question then: How can you protect your business?

Start by getting your team to be extra cautious with login requests. Especially ones that involve entering codes. If you get a device code from someone, stop and think: Did I request this? Do I know for sure this is real?

If you’re not sure, don’t go through with it. Use a separate method, like a direct phone call or your company’s messaging system, to double-check with the person who sent the email.

Remember, real Microsoft logins don’t involve someone else giving you a code to enter. If that ever happens, it’s a red flag.

From a technical side, your IT team (or IT provider) can also tighten things up. If your business doesn’t need device code login as part of its daily operations, it’s safest to turn it off altogether. They can also put in place extra security rules that only allow logins from trusted locations or devices.

And finally, keep training your people. Good cyber security is about awareness. If your team knows what to look out for, they’re much less likely to fall for these kinds of tricks.

Can we help you tighten up your security? Get in touch.

Recent Posts

Messaging app scams are rising.

Messaging app scams are rising.

Messaging app scams are rising. Here’s what businesses need to know. Messaging app scams are becoming a growing risk for businesses of all sizes. Tools like WhatsApp, Microsoft Teams, Signal, and SMS are used every day to keep work moving, but criminals are now using...

Why Passwords Are Still Letting Businesses Down

Why Passwords Are Still Letting Businesses Down

Why Passwords Are Still Letting Businesses Down Most businesses still rely on passwords to protect their systems. However, that approach no longer fits the way people work. Some passwords are strong. Many aren’t. Worse still, people reuse most of them somewhere else....

The hidden cyber risk in everyday web habits

The hidden cyber risk in everyday web habits

The hidden cyber risk in everyday web habits Most cyber attacks don’t start with advanced hacking. They start with everyday behaviour that feels harmless at the time. When work and personal life share the same devices, browsers, and logins, small habits can quietly...

AI at Work: Why People Still Matter More Than Ever

AI at Work: Why People Still Matter More Than Ever

AI at Work: Why People Still Matter More Than Ever   The problem many businesses are feeling   Right now, a lot of people feel uneasy about AI at work. Some worry it might replace jobs. Others feel pressure to keep up with tools they do not fully understand....

Why Multi Factor Authentication isn’t enough!

Why Multi Factor Authentication isn’t enough!

Adversary‑in‑the‑Middle Attacks: Why MFA Alone Isn’t Enough You click a link, sign in, approve the MFA prompt, and get on with your day. Completely unaware that someone else just logged into your account at the same moment. That scenario surprises many organisations,...

AI in IT Operations and Automation

AI in IT Operations and Automation

AI in IT Operations and Automation: What’s Real and What’s Just Hype AI is everywhere right now. Every tool claims to be “AI‑powered”. Every vendor promises faster fixes, fewer issues, and smarter IT. It can all start to sound impressive and confusing at the same...

Why “break‑fix IT” costs more than managed support

Why “break‑fix IT” costs more than managed support

Why “break‑fix IT” costs more than managed support When something breaks, you call IT. When it’s fixed, you pay the bill. On the surface, break‑fix IT feels sensible. You only pay when you need help. No monthly commitment. No long contracts. It can feel like the...