Skip to main content
All lessons
Lesson 4Social Engineering Defense pathway

Stop Device-Code Phishing

A real sign-in page can still approve the wrong device

Highlighted wordsare glossary terms — tap one for a plain-language definition.

A device code is meant to help a television, printer, or other hard-to-type-on device sign in. A criminal can start that same process on their device, then trick you into approving it. The page and code may be real; the request is not.

Know the legitimate flow

Device-code sign-in was created for devices that are difficult to type on, such as smart televisions, printers, and conference-room equipment. The device displays a short code, which you enter into a browser on another device to authorize that specific sign-in. [1, 2]

  • Only enter a device code when you personally started a sign-in on a device in front of you.
  • Match the service, device, and account shown on the approval screen to what you intended.
  • Treat an unexpected code like an unexpected login approval: do not enter or approve it.

See how criminals reverse it

In device-code , the criminal—not your device—starts the sign-in. They send you their code and may direct you to the service's genuine website. If you enter that code and approve access, you can authorize the criminal's session even though the web address is real. [3]

  • Pause when anyone sends you a code or asks you to open a device sign-in page.
  • Do not trust a request just because it uses a genuine Microsoft or other provider page.
  • Leave the message and verify through a contact method you already know.
  • Never enter a code to prove your identity to an incoming caller, texter, or chat participant.

Recognize why this matters now

Microsoft linked the AI-enabled EvilTokens service to more than 12,000 compromised inboxes across over 10,000 organizations. Attackers used stolen access to study email, identify financial relationships, and prepare impersonation and payment-redirection fraud. [3, 4]

  • Warn coworkers if a message asks them to enter a device code on someone else's behalf.
  • Report unusual device-code requests through your organization's security channel.
  • Be especially cautious when the request is tied to a meeting, document, payment, or urgent account problem.

Recover beyond the password

If you entered an unsolicited device code, changing your password may not end the criminal's authorized session. Contact your organization's IT or security team immediately so they can revoke active sessions and refresh tokens, inspect registered devices and inbox rules, and temporarily disable the account when necessary. [3]

  • From a trusted device, change the password and review recent sign-in activity.
  • Sign out other sessions and remove devices or connected apps you do not recognize.
  • Check for new email-forwarding rules, inbox rules, delegates, or recovery methods.
  • Tell your workplace or email provider exactly what happened: you entered an unsolicited device code.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary