
HUGE AI-powered Microsoft Account phishing campaign
Source: YouTube · John Hammond · published Apr 9, 2026 · 15:02
Device code phishing is a technique cybercriminals use to compromise Azure and Microsoft 365 accounts by exploiting Microsoft's legitimate device code authentication process 0:00-0:10.
Key Takeaways:
• Device code authentication works similarly to TV sign-ins where users enter a code to authenticate a device 0:17-0:28
• Microsoft's implementation of this feature is described as extremely over permissive, creating security risks 0:37-0:42
• This method bypasses certain security measures, making it particularly dangerous for organizations 0:44-0:46
Understanding this attack vector is crucial for securing Microsoft cloud environments against sophisticated phishing attempts.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
One of the ways that cyber-criminals steal your Azure Microsoft 365 accounts or take over and compromise your Entra ID identities is with the technique called device code fishing. And this technique takes advantage of a genuine legitimate sign-in process, device code authentication. You can think of it like you're trying to sign in to Netflix on your TV. All you have is your remote, so they give you some random string of letters and numbers, a code, to authenticate that device. And for some reason, Microsoft has support for this, not that you'd ever log in to Outlook or Teams or SharePoint on your TV, but it allows a full sign-in and it is extremely over permissive. And we've covered the device code fish plenty of times on this channel. The most sinister part is that it basically bypasses,…