Your business probably runs on Microsoft 365. Maybe you have multi-factor turned on, the kind where you type a password and then approve a prompt on your phone. That is a real improvement, and it stops the old kind of phishing, the fake login page that copies your password.
This one is different. It does not need your password, and it does not need to beat your phone prompt. It gets you to do the work for it.
The feature you have already used without thinking
When you sign a smart TV or a printer into an account, those screens are miserable to type a password on. So Microsoft built a workaround. The device shows a short code, you open a browser on your phone or laptop, go to Microsoft's real device login page, type the code, and sign in. Now the device in front of you is signed in.
That is a legitimate feature, meant for gear that is awkward to log into. It is also the whole trick.
What the scammer does with it
The attacker starts that same sign-in on their own computer. Microsoft hands them a code, the same way it would hand one to a new TV. Then they send you that code inside a message you would expect to see. A shared document. A voicemail notice. An invoice. A note that claims to be from IT.
You click, you land on Microsoft's actual login page, you type in the code. You sign in with your real username and password. You approve the same multi-factor prompt you have approved a hundred times. Everything on your screen is correct, because it is.
Except the sign-in was never for you. When you approved it, Microsoft handed the key to the computer that started it, the attacker's. They are now inside your email, with the same access you have. Nothing was broken, so no alarm should have gone off. Every step happened on Microsoft's real site.
Why a new password does not always end it
This is the part that catches people flat-footed. Because the attacker did not steal your password, changing your password afterward may not remove them. What they walked away with is a session token, a kind of long-lived key Microsoft issues once you are signed in. Those keys can keep working even after a password reset. Researchers at Huntress, who watch this attack across thousands of companies, call it token theft, and it is why the cleanup is bigger than just picking a new password.
This stopped being a fringe trick
Through 2025, this was mostly a nation-state technique: careful, rare, aimed at governments and defense contractors. In 2026 it became a product you could buy. Microsoft's Digital Crimes Unit shut down one such service, called EvilTokens, in September 2026. Before the takedown, Microsoft linked it to more than 12,000 compromised inboxes at over 10,000 organizations worldwide. Huntress measured these attacks rising 1,380% between July to December 2025 and January to April 2026, and counted 344 victim organizations in a single wave.
The businesses caught up in it were ordinary ones: wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Microsoft's own warning after the takedown was blunt. The infrastructure was disrupted, but the model behind it will not disappear with it.
The one rule worth teaching
You cannot train people to spot a fake web address here, because the address is real. The rule that actually works is simpler.
Never enter a code into a Microsoft or Google sign-in page unless you started the sign-in yourself, on a device sitting in front of you.
A code that arrives by email, by text, or over the phone is not a sign-in you started. That should stop the person cold. If it helps, print it on a card and tape it by the register.
What to ask for this week
There is no patch for this, because nothing is broken. It comes down to one setting and one habit.
Ask whether the device code sign-in flow is blocked for your company. Microsoft's own guidance is to block it wherever it is not genuinely needed and allow it only for the handful of devices that require it. Most office staff never use it at all.
Ask about phishing-resistant sign-in, the kind built on a passkey or a physical security key. It holds up against this better than a code sent to your phone.
Ask whether anyone is actually reading the sign-in logs for device code events. They are rare enough that a single stray one stands out.
And settle one thing before you need it. If you ever think someone entered a code they were sent, the first move is to sign that person out of all sessions, not just change their password.
Keep it in proportion
Most weeks, nothing happens. This is not a reason to distrust your email or the tools you pay for. It is a reason to know the one pattern that slips past what you already have, and to close a door that takes a few minutes to close.