Device Code Phishing: How Our Customers Were Protected Overnight

Posted: March 21, 2026Category:

Huntress — guaranteed to lower your stress levels.

Huntress proactively secured all our customers’ Microsoft 365 tenants overnight in response to a major device code phishing attack. This proactive approach ensures threats are addressed before they can cause harm.

Summary of the issue

Device code phishing involves an attacker generating a valid Microsoft login code to trick the victim into entering it on an official login page. The victim believes they are accessing a legitimate service but is actually authorising the attacker’s session.

Solution for our customers

Huntress added a Conditional Access Policy to all our customers’ Microsoft 365 tenants to block the attackers. Since implementing these policy blocks, Huntress has successfully blocked 81 attacks across the Microsoft 365 tenants they protect.

This is what managed security should look like — fixed before you ever hear about it. See our security services.

Contact us today