The MFA Bypass Epidemic: Device Code Phishing
- Scott Pagel

- Jun 8
- 5 min read

Having MFA enabled does not mean your accounts are protected. In 2026, that assumption is exactly what attackers are counting on.
A phishing-as-a-service platform called Kali365 emerged in 2026 and is helping attackers compromise Microsoft 365 accounts without stealing passwords or intercepting MFA codes. Instead, attackers are abusing legitimate Microsoft authentication workflows to capture authenticated session tokens and gain access after MFA has already been completed.
In other words, the attackers are not bypassing MFA by breaking it. They are bypassing using device code phishing and abusing the trust that comes after it. And that changes how organizations need to think about identity security.
The Rise of Device Code Phishing
Traditional phishing attacks attempt to steal usernames, passwords, or MFA codes.
Device code phishing works differently.
The attack abuses Microsoft's OAuth 2.0 Device Authorization Grant, a legitimate authentication workflow designed to help devices with limited input capabilities authenticate users.
When used properly, this workflow allows users to enter a device code into Microsoft and authorize access.
Attackers simply insert themselves into the process.
Victims receive what appears to be a legitimate Microsoft authentication request and complete the login process themselves. The user enters their credentials, completes MFA, and unknowingly grants the attacker a valid authentication session.
No password theft.
No MFA interception.
No malware required.
The attacker simply receives a legitimate Microsoft session token that allows access to Microsoft 365 resources as the authenticated user.
That is why these attacks are proving so effective.
The user does everything correctly.
And the account still becomes compromised.
This Is Not a Small-Scale Threat
Many organizations hear about new attack techniques and assume they are isolated incidents targeting large enterprises.
That is not what is happening here.
Between April 14 and April 16, coordinated device code phishing campaigns reportedly targeted more than 35,000 users across over 13,000 organizations spanning 26 countries.
Healthcare providers.
Financial services firms.
Professional services organizations.
These are exactly the types of businesses that rely heavily on Microsoft 365 and cloud-based collaboration platforms.
They are also the types of organizations SafeStorz works with every day.
The reality is that attackers increasingly prefer targeting organizations that have already adopted modern security controls because they know traditional credential theft is becoming less effective.
When MFA becomes standard, attackers adapt.
And they have.
Why MFA Alone Is No Longer Enough
MFA remains essential.
Organizations should absolutely continue enforcing it.
The problem is assuming MFA is the finish line instead of one layer within a broader identity security strategy.
Modern attacks increasingly focus on:
Session token theft
OAuth abuse
Device registration abuse
Conditional Access bypass techniques
Identity-based lateral movement
Cloud application compromise
Once attackers obtain a legitimate authenticated session, many traditional security controls no longer help.
The system believes the user has already proven who they are.
From Microsoft's perspective, the login is valid.
That is exactly why device code phishing is so dangerous.
The attacker is operating within the trust model itself.

What SafeStorz Sees in Real Environments
One of the most common assumptions SafeStorz encounters during Microsoft 365 assessments is the belief that enabling MFA automatically closes the door on identity compromise.
In reality, identity security depends on multiple layers working together.
Conditional Access policies
Device compliance requirements
Identity governance
Threat detection
Session monitoring
Security baselines
Without those additional controls, businesses often develop blind spots they never realize exist.
This is one reason SafeStorz standardizes Microsoft 365 and Intune deployments rather than allowing every environment to evolve differently. Consistent Conditional Access policies, device compliance enforcement, and identity security controls reduce the opportunities attackers have to abuse authentication workflows.
Security should not depend on a single control doing all the work.
The FBI Recommendation: Restrict Device Code Authentication
Federal authorities are already responding to the rise of device code phishing.
One of the primary recommendations is to restrict or fully block device code authentication flows wherever possible through Microsoft Conditional Access policies.
For many organizations, that authentication method is rarely needed in daily operations.
Disabling unnecessary authentication pathways reduces the attack surface available to adversaries.
This is not a future recommendation.
It is something businesses should be evaluating right now.
And it is already part of the identity hardening approach SafeStorz implements for many Microsoft 365 environments.
The goal is not simply enabling security features.
The goal is understanding which features introduce risk and configuring them appropriately.
Why Detection Matters Just as Much as Prevention
Even properly configured environments can still face identity-based attacks.
That is why prevention alone is not enough.
Organizations also need visibility into suspicious behavior after authentication occurs.
This is where SafeStorz's layered security model becomes important.
Conditional Access policies help reduce exposure.
But if an attacker obtains a valid session token, additional detection capabilities become critical.
SafeStorz uses Cynet XDR with 24/7 MDR to identify behaviors that traditional authentication controls may miss, including:
Unusual login activity
Suspicious authentication patterns
Abnormal user behavior
Privilege escalation attempts
Lateral movement activity
Cloud-based attack indicators
The value is not simply the technology.
It is having security analysts actively monitoring and responding when suspicious activity occurs.
Because attackers do not always trigger alerts during initial access.
Often, the real indicators appear after they are already inside.
Why Infrastructure Architecture Still Matters
Identity security is increasingly becoming the primary battleground in cybersecurity.
But infrastructure design still matters.
A compromised Microsoft 365 account should not automatically provide access to every critical system inside an organization.
One reason SafeStorz emphasizes private cloud infrastructure, segmentation, and reduced blast radius architecture is because compromise should not dictate outcomes.
If an attacker gains access to an account, the environment should still limit what that account can reach.
Security is strongest when layers work together:
MFA
Conditional Access
Device compliance
Threat detection
Network segmentation
Private cloud isolation
Continuous monitoring
No single control is perfect.
Resilience comes from combining them.
The New Reality of Identity Security
The Kali365 campaigns highlight an important shift in cybersecurity. Attackers are no longer focused solely on stealing credentials.
They are increasingly focused on stealing trust.
The authentication process itself is becoming the target.
That means organizations need to move beyond the idea that checking the MFA box solves the problem.
MFA is still critical.
But it is only one piece of modern identity security.
SafeStorz helps organizations strengthen Microsoft 365 environments through Conditional Access hardening, Intune standardization, identity security reviews, Cynet MDR, and private cloud architectures designed to reduce risk when attackers inevitably adapt.
Because in 2026, the question is no longer whether you have MFA.
The question is what happens when an attacker finds a way around it.
Additional Reading
Guardz - The Rise of Kali365 and Why MSPs Should Be Concerned
SpyCloud - Device Code Phishing: The New AiTM Attack Bypassing MFA
BleepingComputer - FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
Red Sift - Email Security Roundup: AitM & AI Phishing Rise (April 2026)
Barracuda - The ‘code of conduct’ phishing campaign: What MSPs need to know
Push Security - Analyzing the rise in device code phishing attacks in 2026
The Hacker News - Microsoft Details Phishing Campaign Targeting 35,000 Users Across 26 Countries
MSFT News Now - Microsoft warns of multi-stage ‘code of conduct’ AiTM phishing campaign



