Tendvane

← All articles

AccountsSeptember 23, 2026

The sign-in page was real, the code was not, and 12,000 inboxes opened

The code arrives by email. You click the button, land on microsoft.com/devicelogin, which is Microsoft's genuine page, and type the code in. That is the entire attack.

Microsoft's Digital Crimes Unit said on 22 September that it had pulled apart EvilTokens, a phishing service sold through a Telegram shopfront for a $1,500 joining fee and $500 a month. Working under a court order from the Eastern District of Virginia, it seized 50 websites and disabled more than 150 further domains. The Metropolitan Police arrested two men, aged 32 and 38, in London on 11 September; both were released on bail while the investigation continues. Between February and June, customers of the service got into more than 12,000 inboxes across over 10,000 organisations, concentrated in the US, Canada, the UK, Australia, India and France.

Device code phishing works because nothing about it looks wrong. The sign-in page is authentic, the address bar is correct, and the two-factor prompt behaves exactly as it should, because you genuinely are signing in. The only lie is about who asked. The criminal generated that code, and when you approve it the access token goes to them rather than to you. No password ever changes hands, which is why changing yours afterwards achieves nothing.

The rule that keeps you safe is short. A device code is for signing in to something that cannot easily take a password, like a TV app or a games console, and the code should have appeared on that device first. If one reaches you in a message and you did not start a sign-in yourself, do not type it anywhere. Microsoft added a blunt line about the aftermath that is worth carrying with you: assume a compromised mailbox has been read within minutes, not days. Tendvane's privacy and accounts check goes through the sign-in and account settings on your PC and tells you plainly what is exposed.

Sources

Download Tendvane