Skip to content
Hackers Exploit Device Code Phishing to Compromise Microsoft Entra Accounts

Hackers Exploit Device Code Phishing to Compromise Microsoft Entra Accounts

First seen 21 Feb 2026, 00:17 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

Hackers are targeting Microsoft Entra accounts through a combination of device code phishing and voice phishing (vishing). Victims, primarily from technology, manufacturing, and financial sectors, are deceived into entering device codes that attackers use to gain unauthorized access. The attacks exploit the OAuth 2.0 Device Authorization flow, utilizing legitimate Microsoft OAuth client IDs.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-02-19
Bleepingcomputer reports on device code vishing attacks
2026-02-20
Winbuzzer reports on phishing defenses being bypassed

More articles in this cluster (2)

Following this threat?

Track Okta in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed