Microsoft Entra Accounts Under Attack: Device Code Vishing Explained (2026)

Microsoft Entra Accounts Targeted in Device Code Vishing Attacks: A Growing Threat

Hackers are employing a sophisticated technique to compromise Microsoft Entra accounts, combining device code phishing and voice phishing (vishing) to exploit the OAuth 2.0 Device Authorization flow. This method is particularly insidious as it leverages legitimate Microsoft OAuth client IDs and device authorization flows, making it harder for victims to detect the attack.

Instead of traditional phishing sites, attackers use legitimate Microsoft login forms and standard device code authentication workflows to breach corporate accounts. This approach provides valid authentication tokens, allowing access to the victim's account without stealing passwords or intercepting multi-factor authentication codes.

The ShinyHunters extortion gang is believed to be behind these attacks, according to a source speaking to BleepingComputer, a claim later confirmed by the threat actors themselves. ShinyHunters has a history of vishing attacks, previously targeting Okta and Microsoft Entra SSO accounts for data theft.

Device code social engineering attacks are becoming more prevalent, no longer requiring attacker-controlled infrastructure. Attackers use open-source tools to generate device codes and user codes, which they then share with targets. The goal is to convince employees to enter these codes on the Microsoft device authentication page, microsoft.com/devicelogin.

Once the targeted person authenticates, the attackers can retrieve the refresh token and exchange it for access tokens, granting them access to the employee's Microsoft services without re-authenticating via multi-factor authentication. This enables the theft of corporate data for extortion.

KnowBe4 Threat Labs has also uncovered a campaign using traditional phishing emails and websites to deliver device code attacks, relying on social engineering lures like fake payment prompts and document-sharing alerts. Microsoft 365 account holders are advised to block malicious domains, audit OAuth app consents, and review Azure AD sign-in logs for device code authentication events.

Administrators are recommended to disable the device code flow when not required and enforce conditional access policies. Device code phishing is not new, with Russian hackers targeting Microsoft 365 accounts using this method in 2025, and similar attacks reported by ProofPoint in December of the same year.

As IT infrastructure becomes more complex, the need for robust security measures becomes increasingly vital. Modern IT infrastructure moves faster than manual workflows can handle, making it essential to stay vigilant against evolving cyber threats.

Microsoft Entra Accounts Under Attack: Device Code Vishing Explained (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 6223

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.