JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
Russian state-sponsored hackers have launched a sophisticated phishing campaign targeting Microsoft 365 accounts using a technique called device code phishing. This method, designed for devices lacking browser capabilities, involves attackers impersonating trusted officials to lure users into providing access codes via messenger apps. Once the target enters the code, the attackers gain unauthorized access to the account, exploiting the ambiguity of the device code authentication process. Security experts urge vigilance, as these attacks have proven more effective than previous phishing efforts.
What steps do you take to verify the authenticity of unexpected access requests?