{
  "slug": "device-code-phishing",
  "title": "Device code phishing: the page is real, and that is the problem",
  "summary": "Device code phishing has no fake page and no stolen password. The victim authenticates on the genuine provider site. Why MFA does not stop it, and what does.",
  "lede": "There is no lookalike domain. There is no fake login form. The victim types a code into the genuine Microsoft page, approves with their genuine passkey, and hands an attacker a working session. Every control built to spot a fake page is looking in the wrong place, because there is no fake page to spot.",
  "date": "2026-09-15",
  "reading_time": "17 min read",
  "category": "Security",
  "tags": ["device code phishing", "OAuth", "RFC 8628", "Microsoft 365", "MFA bypass", "Storm-2372", "consent"],
  "image": "https://cdn.twc.sh/images/igcache/Device%20Code%20Phishing/1200_630/blog.jpg",
  "url": "/blog/device-code-phishing.html",
  "wordcount": 4776,
  "related": ["session-theft-aitm", "blind-signing-wysiwys", "passkeys-prove-login-not-transaction"],
  "schema": "Article"
}
