Highlighted wordsare glossary terms — tap one for a plain-language definition.
A device code is meant to help a television, printer, or other hard-to-type-on device sign in. A criminal can start that same process on their device, then trick you into approving it. The page and code may be real; the request is not.
Know the legitimate flow
Device-code sign-in was created for devices that are difficult to type on, such as smart televisions, printers, and conference-room equipment. The device displays a short code, which you enter into a browser on another device to authorize that specific sign-in. [1, 2]
- Only enter a device code when you personally started a sign-in on a device in front of you.
- Match the service, device, and account shown on the approval screen to what you intended.
- Treat an unexpected code like an unexpected login approval: do not enter or approve it.
See how criminals reverse it
In device-code PhishingWhat it means: A deceptive email or message designed to make you click, share information, send money, or give account access.Example: An “unpaid delivery fee” text with a link to a page that looks like the post office.What to do: Don't tap links in unexpected messages — open the company's app or type its address yourself.Important: Real companies never ask for your password or a login code by message.What does this mean?, the criminal—not your device—starts the sign-in. They send you their code and may direct you to the service's genuine website. If you enter that code and approve access, you can authorize the criminal's session even though the web address is real. [3]
- Pause when anyone sends you a code or asks you to open a device sign-in page.
- Do not trust a request just because it uses a genuine Microsoft or other provider page.
- Leave the message and verify through a contact method you already know.
- Never enter a code to prove your identity to an incoming caller, texter, or chat participant.
Recognize why this matters now
Microsoft linked the AI-enabled EvilTokens service to more than 12,000 compromised inboxes across over 10,000 organizations. Attackers used stolen access to study email, identify financial relationships, and prepare impersonation and payment-redirection fraud. [3, 4]
- Warn coworkers if a message asks them to enter a device code on someone else's behalf.
- Report unusual device-code requests through your organization's security channel.
- Be especially cautious when the request is tied to a meeting, document, payment, or urgent account problem.
Recover beyond the password
If you entered an unsolicited device code, changing your password may not end the criminal's authorized session. Contact your organization's IT or security team immediately so they can revoke active sessions and refresh tokens, inspect registered devices and inbox rules, and temporarily disable the account when necessary. [3]
- From a trusted device, change the password and review recent sign-in activity.
- Sign out other sessions and remove devices or connected apps you do not recognize.
- Check for new email-forwarding rules, inbox rules, delegates, or recovery methods.
- Tell your workplace or email provider exactly what happened: you entered an unsolicited device code.
Why Hygi. recommends this — the guidance above follows these published sources:
Microsoft Learn
OAuth 2.0 device authorization grant(opens in a new tab)How legitimate device-code sign-in works.
Internet Engineering Task Force
RFC 8628 — OAuth 2.0 Device Authorization Grant(opens in a new tab)The underlying standard, including remote-phishing safeguards in Section 5.4.
Microsoft Security
Unmasking EvilTokens: Getting to the root of device code phishing(opens in a new tab)Attack method, observed scale, and incident-response guidance.
Microsoft Digital Crimes Unit
Disrupting EvilTokens: The AI chatbot built for cybercrime(opens in a new tab)Evidence of the campaign's reach and criminal use.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary