How device code phishing gives scammers access to your account

Imported from official source

Cybersecurity Classified by Officially

You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.

The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.

The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.

Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in. This allows the app or device that displayed the code to access your account.

In this phishing attack, the scammer starts the sign-in and gets you to enter the code and approve the request. That can give the scammer access to your account.

How device code phishing works

Device code phishing relies on the OAuth 2.0 Device Authorization Grant, a standard sign-in method for devices with no browser or limited input.

An attack generally follows these steps:

  1. An attacker starts a legitimate device code sign-in request for an app or device they control.
  2. The sign-in service generates a short, temporary code and a legitimate verification page.
  3. The attacker uses social engineering, such as a fake Teams invite, a document-sharing request, or an invitation to join a “secure” chat, to pass that code to the victim.
  4. The victim visits the genuine sign-in page, enters the code, and approves the request.
  5. The attacker’s waiting device receives authentication tokens.

Those tokens act as digital passes, allowing the attacker to access the victim’s account without knowing their password.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/how-to/2026/09/how-device-code-phishing-gives-scammers-access-to-your-account

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 23, 2026 20:00
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/how-to/2026/09/how-device-code-phishing-gives-scammer...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.