Hackers Exploit Device Code Phishing to Compromise Microsoft Entra Accounts

Hackers Exploit Device Code Phishing to Compromise Microsoft Entra Accounts

First seen 21 Feb 2026, 00:17 UTC BleepingcomputerWinbuzzer 77% similarity 24.3

Article Content

Browse articles
ThreatCluster

Hackers are targeting Microsoft Entra accounts through a combination of device code phishing and voice phishing (vishing). Victims, primarily from technology, manufacturing, and financial sectors, are deceived into entering device codes that attackers use to gain unauthorized access. The attacks exploit the OAuth 2.0 Device Authorization flow, utilizing legitimate Microsoft OAuth client IDs.

ThreatCluster AI

Timeline

2026-02-19
Bleepingcomputer reports on device code vishing attacks
2026-02-20
Winbuzzer reports on phishing defenses being bypassed

Community

Browse all →