What happened
Microsoft Threat Intelligence published details in February 2025 of an active campaign by the actor it tracks as Storm-2372, which abused the OAuth device code authentication flow to take over Microsoft 365 accounts. Targets spanned government, NGOs, IT services, defence, telecommunications, health and energy across Europe, North America, Africa and the Middle East. The campaign had been running since at least August 2024.
How the deception worked
The actor built rapport first, messaging targets over WhatsApp, Signal or Teams while posing as a prominent person relevant to the victim's work. It then sent what looked like an invitation to a Teams meeting or a document, containing a genuine Microsoft device code page and a code to type in. Because the sign-in page was real Microsoft infrastructure and the victim entered the code themselves, the flow looked entirely legitimate and MFA prompts appeared expected. Completing it issued the attacker valid access and refresh tokens for the victim's account, giving persistent mailbox and file access without ever handling a password.
The control that would have caught it· our reading, not a claim from the sources
Disable the device code authentication flow where it is not needed via Conditional Access, and train staff that a legitimate meeting invitation never requires typing a code into a separate sign-in page.
Sources (2)
- Storm-2372 conducts device code phishing campaignMicrosoft Security·microsoft.comOpen ↗
- Phishing campaign targets Microsoft device-code authentication flowsCybersecurity Dive·cybersecuritydive.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.