Winbuzzer
Hackers Exploit Device Code Phishing to Compromise Microsoft Entra Accounts
First seen 21 Feb 2026, 00:17 UTC
•
•77% similarity
•24.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Hackers are targeting Microsoft Entra accounts through a combination of device code phishing and voice phishing (vishing). Victims, primarily from technology, manufacturing, and financial sectors, are deceived into entering device codes that attackers use to gain unauthorized access. The attacks exploit the OAuth 2.0 Device Authorization flow, utilizing legitimate Microsoft OAuth client IDs.
ThreatCluster AI
Timeline
2026-02-19
Bleepingcomputer reports on device code vishing attacks
2026-02-20
Winbuzzer reports on phishing defenses being bypassed