← Back to blog

DVG Systems Cybersecurity

Device Code Phishing: The M365 Attack That Bypasses MFA

5 min read
On this page

This week, our security partner Huntress identified a large-scale phishing campaign targeting Microsoft 365 tenants across hundreds of organizations — including businesses right here in Northern Ontario.

We’re sharing this because transparency matters. Our clients were protected before we even had to pick up the phone. Here’s what happened and why it matters for any business running Microsoft 365.

What Happened

Over the past two weeks, Huntress observed a new phishing campaign using device code phishing — a technique that tricks users into authenticating on a legitimate Microsoft login page, then hijacks that authentication token to gain access to their Microsoft 365 account.

What makes this campaign particularly dangerous:

  • AI-generated phishing lures — the emails are personalized and well-written, bypassing traditional email filters that look for obvious red flags
  • Legitimate infrastructure — the attackers are routing their campaign through Railway, a popular platform-as-a-service tool, making the traffic harder to block by reputation alone
  • Device code flow abuse — instead of stealing passwords directly, this technique exploits Microsoft’s own device authentication workflow, which many users don’t recognize as a threat

This isn’t a run-of-the-mill phishing attempt. It’s a coordinated campaign with advanced tactics designed to defeat both technical controls and human judgment.

What We Did About It

DVG Systems uses Huntress Identity Threat Detection and Response (ITDR) to monitor our clients’ Microsoft 365 environments around the clock. When Huntress identified this campaign, they took immediate action:

  1. Deployed a Conditional Access Policy across all protected tenants — this policy, named “[HUNTRESS] Block - Confirmed Adversary Infrastructure,” blocks authentication from any IP range associated with the threat
  2. Created a Named Location containing the attacker’s infrastructure in CIDR notation, so any login attempt from those networks is automatically denied
  3. Confirmed that no client accounts were compromised — Huntress SOC analysts verified that all activity was caught and blocked

This happened automatically. Our clients didn’t need to do anything. That’s the difference between reactive IT and proactive managed security.

Why Device Code Phishing Works

Traditional phishing sends you to a fake login page. Device code phishing is more subtle.

Here’s how it works:

  1. You receive an email (often well-crafted and personalized) asking you to sign in to a Microsoft service
  2. The email directs you to microsoft.com/devicelogin — Microsoft’s real, legitimate authentication page
  3. You’re asked to enter a code provided in the email
  4. When you authenticate, you’re not logging into your account — you’re authorizing the attacker’s device to access your account on your behalf

Because the login page is genuinely Microsoft’s, most users don’t think twice. And because the attacker gets an OAuth token rather than your password, MFA alone doesn’t stop it.

What Northern Ontario Businesses Should Do

If your organization uses Microsoft 365, here are the steps that actually matter:

Immediate actions:

  • Train your team to recognize device code phishing — if anyone asks you to go to microsoft.com/devicelogin and enter a code, stop and verify with IT first
  • Review your Conditional Access Policies — if you don’t have any, you’re relying entirely on passwords and MFA
  • Check your sign-in logs for unfamiliar device code authentications

Structural defenses:

  • Identity Threat Detection and Response (ITDR) — tools like Huntress monitor your M365 tenant for suspicious sign-ins, impossible travel, and token abuse in real time
  • Conditional Access Policies — restrict authentication by location, device compliance, and risk level
  • Phishing-resistant MFA — FIDO2 security keys or Windows Hello are resistant to phishing and credential theft attacks

The AI Factor

This campaign is notable because the phishing lures are AI-generated. That means:

  • No more obvious spelling mistakes or awkward phrasing
  • Emails are personalized to the recipient and their organization
  • Traditional “look for bad grammar” training is becoming obsolete

The security landscape is changing. Businesses in Thunder Bay and across Northern Ontario need partners who are watching for threats like this around the clock — not just responding after the damage is done.

Our Approach

At DVG Systems, every managed IT client gets identity threat detection and response (ITDR) as part of their bundle. It’s not an add-on or an upsell — it’s how we believe Microsoft 365 should be protected.

When this campaign hit, our clients were already covered. The block was in place before most organizations even knew the threat existed.

If you’re running Microsoft 365 without this level of monitoring, you’re relying on your users to outsmart AI-generated phishing emails. That’s not a bet we’d take.

Book a free security assessment →

We’ll review your current Microsoft 365 security posture, check your Conditional Access Policies, and show you exactly where the gaps are. No obligation, no sales pressure — just a clear picture of where you stand.

You can also reach us at (807) 700-0061 or solutions@dvgsystems.com.


DVG Systems is a Thunder Bay-based managed IT provider serving businesses across Northern Ontario. Identity threat detection and response for Microsoft 365, monitored 24/7, is part of every managed IT bundle.

Ask AI

Accessibility