MalwareZero
An open laptop glowing blue on a dark kitchen table at night, with a set of keys on an envelope and a phone lying face down beside it.
No password changes hands in this trick. A short code does the work instead.

What to do

Entered a code at microsoft.com/devicelogin or approved an app? What to do now

Updated 23 September 2026

Device code phishing and consent phishing are two versions of the same trick: instead of stealing your password, the scammer gets you to approve their access on the genuine Microsoft or Google website. Your password and your two-factor code never leave your hands, which is exactly why it works. On September 22, 2026, Microsoft said it had taken down EvilTokens, a phishing service built on this method that had broken into more than 12,000 email inboxes, and the FBI warned about the app-approval version on September 1. The fix takes about fifteen minutes, but the order matters.

How can someone get into my account without my password?

Big sign-in systems let you grant access without typing a password into the thing that wants access. That is a good design. It is why you can sign in to a streaming app on your TV by entering a short code on your phone, and why a calendar app can read your Outlook calendar without ever seeing your password. The access comes as a token: a digital pass that says "this person approved this."

Both scams simply point that approval at the wrong party.

In both cases every page you type into is genuine. The address bar is right, the padlock is there, your two-factor prompt arrives as normal. The advice to check that a website is real before you sign in still matters, but here it does not save you, because the website is real. What gives the trick away is how you got there.

What was EvilTokens?

EvilTokens was a subscription service that sold device code phishing to other criminals. Microsoft tracks the group behind it as Storm-2992. According to Microsoft's threat intelligence write-up, customers paid $1,500 up front plus $500 a month and got 44 ready-made email themes: invoices, requests for proposals, shared files, document signing, Microsoft cloud notices and "password expiring" warnings among them.

The email led to a page that showed a live code with a "Copy Code" button, and often copied the code to your clipboard without asking. It then sent you to the real microsoft.com/devicelogin to paste it. In the background, the page checked with the criminals' server every few seconds to see whether you had finished. Once you had, they were in.

What they did next is the part to take seriously. Microsoft says the attackers created inbox rules and registered new devices on the account so they could keep coming back, and some waited several hours before touching anything, to avoid setting off alarms. Microsoft's Digital Crimes Unit also found a built-in AI chatbot that read through victims' inboxes to find payment approvals, trusted contacts and other openings for fraud. Its warning to organizations: assume a criminal can understand a stolen inbox "in minutes, not days."

Key facts and dates

A takedown slows a service down. It does not retire the technique. The device code flow still exists because TVs and printers need it, and copies of the kits will outlive the people who sold them.

What does the message look like?

The lures are dull on purpose. The ones Microsoft catalogued read like normal work mail: a bid proposal, a partnership agreement, a benefits update, a document waiting for your signature, a shared file, or a note that your password is about to expire. The FBI's warning about consent phishing describes a more personal approach, with messages that pose as officials, journalists or event organizers and invite you to an interview, a panel or a shared folder.

These are the tells worth memorizing:

Scammers have long tried to get you to read out a one-time code on the phone, the same pattern behind the Apple ID and iCloud storage messages and fake bank fraud alerts. The device code version just moves that request onto a web page and makes you type the code yourself.

I already typed the code or approved the app. What now?

Work through these in order. The order matters because a password change alone does not throw out a token the attacker already holds. The FBI puts it plainly: access from a consent phishing app "can only be revoked by the victim invalidating the token in their application security settings; not by changing the password."

If it was a work or school account

Tell your IT or security team now, before anything else, and tell them exactly what you typed and where. They can do things you cannot: revoke every sign-in session and refresh token on your account, check for devices the attacker registered, find inbox rules, and see whether the same email reached colleagues. Microsoft's own guidance to administrators is to revoke sessions and consider temporarily disabling the account. An early call to IT looks nothing like carelessness from their side. It is the report they were hoping someone would make.

If you approved an app, you can also remove it yourself from the My Apps portal: find the app, choose Manage your application, then Revoke permissions. Permissions an administrator granted cannot be removed there, which is one more reason to involve IT.

If it was a personal Microsoft account (Outlook.com, Hotmail, Live)

  1. Remove apps you do not recognize. Go to account.live.com/consent/Manage, the page Microsoft calls "apps and services that can access your data." Open anything unfamiliar and remove its permissions.
  2. Sign out everywhere. In your Microsoft account's advanced security options, choose Sign out everywhere. Microsoft says this can take up to 24 hours and does not cover Xbox consoles, which you sign out separately.
  3. Change your password, and if you use the same password anywhere else, change it there too.
  4. Check your mail rules and forwarding. In Outlook.com settings, look at the rules list and the forwarding option. A rule that moves or deletes messages from your bank, a colleague or "invoice" emails, or a forwarding address you did not set, is the attacker's work. Delete it.
  5. Check your recent activity and devices on the account's security page and remove anything you do not own.

If it was a Google account

Consent phishing works on Google accounts too. Go to myaccount.google.com/linkedapps, open each app you do not recognize, choose See details, then Remove access. Google's help page is clear that once you remove access, the app cannot get into your account anymore. Then change your password and check Gmail's filters and forwarding settings for anything you did not create. Removing access stops new reading; it does not pull back what was already copied, so treat anything in that inbox as seen.

What could they have done with my inbox?

More than read it. An inbox is where password resets arrive, so an attacker in your email can often reset other accounts. It holds invoices, bank letters, tax forms and scans of IDs. And it lets them write to your contacts as you, which is the real prize in the business version of this scam: a message from your own address telling a client that your bank details have changed.

After you have locked things down, spend a few minutes on the follow-up:

If money has already moved because of a message sent from your account, go to I paid a scammer: what now. Calling the bank within hours makes a real difference to what can be recovered.

Does two-factor authentication stop this?

Not the kind most people use. With a text code or an app prompt, you are the one completing the check, on the real site, so the scammer gets a sign-in that has already passed two-factor. That is the whole selling point of device code phishing to the people who bought it.

Phishing-resistant sign-in, meaning passkeys and hardware security keys, is the direction Microsoft points organizations toward, and it is worth turning on for personal accounts where your provider offers it. Organizations can also switch off device code sign-in for people who have no need for it. For everyone else, the protection is a habit rather than a setting: only type a device code that your own device just showed you.

How to check a code or app request safely

When a message asks you to approve anything, ask where the request started. If you are standing in front of a new TV or setting up a printer and it shows a code, that is the normal flow. If the code arrived from someone else, stop.

For a document someone says they shared, open OneDrive, SharePoint or Google Drive directly from your own bookmark or app and look in "Shared with me." If it is not there, contact the sender using an address or number you already had, not the one in the message. For a request that seems to come from a colleague or a journalist, the same rule applies. The FBI's advice is to verify who you are dealing with independently and only authorize apps you trust.

If you suspect you are being targeted, save the message. The FBI asks for screenshots of the suspicious messages with a report at ic3.gov or to your local field office, and your email provider can use the original message to block the next one. Our page on where to report a scam lists the other places that take reports.

Quick answers

Is microsoft.com/devicelogin a scam site?
No. It is Microsoft's real page for signing in smart TVs, printers and other devices without a keyboard. The scam is the code. If an email or website gave you the code, and you were not setting up a device of your own, typing it there signs someone else into your account.
I entered the code but closed the window straight away. Am I safe?
Assume not. The attacker's page checks every few seconds for your approval, so access is granted the moment you finish signing in. Sign out everywhere, change your password, check your mail rules and forwarding, and tell your IT team if it was a work account.
Will changing my password remove an app I approved?
No. The FBI says access from a consent phishing app can only be revoked by removing the app in your account's security settings, not by changing the password. Remove the app first at account.live.com/consent/Manage for Microsoft or myaccount.google.com/linkedapps for Google.
Does two-factor authentication stop device code phishing?
Not the kind that sends you a code or a prompt. You complete the two-factor step yourself on the real Microsoft page, and the attacker receives the finished sign-in. Passkeys and hardware security keys are harder to misuse, but the best defense is never entering a code you did not request.
Who should I report this to?
If it was a work or school account, your IT or security team first, because they can revoke sessions you cannot. Then file a report at ic3.gov with screenshots of the message, as the FBI asks, and at ReportFraud.ftc.gov if money was lost or requested.