top of page

The MFA Bypass Epidemic: Device Code Phishing

  • Writer: Scott Pagel
    Scott Pagel
  • Jun 8
  • 5 min read
SafeStorz cybersecurity slide: orange shield and lock icons on black, titled The MFA Bypass Epidemic, warning about MFA bypass threats

Having MFA enabled does not mean your accounts are protected. In 2026, that assumption is exactly what attackers are counting on.


A phishing-as-a-service platform called Kali365 emerged in 2026 and is helping attackers compromise Microsoft 365 accounts without stealing passwords or intercepting MFA codes. Instead, attackers are abusing legitimate Microsoft authentication workflows to capture authenticated session tokens and gain access after MFA has already been completed.


In other words, the attackers are not bypassing MFA by breaking it. They are bypassing using device code phishing and abusing the trust that comes after it. And that changes how organizations need to think about identity security.


The Rise of Device Code Phishing


Traditional phishing attacks attempt to steal usernames, passwords, or MFA codes.

Device code phishing works differently.


The attack abuses Microsoft's OAuth 2.0 Device Authorization Grant, a legitimate authentication workflow designed to help devices with limited input capabilities authenticate users.


When used properly, this workflow allows users to enter a device code into Microsoft and authorize access.


Attackers simply insert themselves into the process.


Victims receive what appears to be a legitimate Microsoft authentication request and complete the login process themselves. The user enters their credentials, completes MFA, and unknowingly grants the attacker a valid authentication session.


No password theft.


No MFA interception.


No malware required.


The attacker simply receives a legitimate Microsoft session token that allows access to Microsoft 365 resources as the authenticated user.


That is why these attacks are proving so effective.


The user does everything correctly.


And the account still becomes compromised.


This Is Not a Small-Scale Threat


Many organizations hear about new attack techniques and assume they are isolated incidents targeting large enterprises.


That is not what is happening here.


Between April 14 and April 16, coordinated device code phishing campaigns reportedly targeted more than 35,000 users across over 13,000 organizations spanning 26 countries.


Healthcare providers.

Financial services firms.

Professional services organizations.


These are exactly the types of businesses that rely heavily on Microsoft 365 and cloud-based collaboration platforms.


They are also the types of organizations SafeStorz works with every day.


The reality is that attackers increasingly prefer targeting organizations that have already adopted modern security controls because they know traditional credential theft is becoming less effective.


When MFA becomes standard, attackers adapt.


And they have.


Why MFA Alone Is No Longer Enough


MFA remains essential.


Organizations should absolutely continue enforcing it.


The problem is assuming MFA is the finish line instead of one layer within a broader identity security strategy.


Modern attacks increasingly focus on:

  • Session token theft

  • OAuth abuse

  • Device registration abuse

  • Conditional Access bypass techniques

  • Identity-based lateral movement

  • Cloud application compromise


Once attackers obtain a legitimate authenticated session, many traditional security controls no longer help.


The system believes the user has already proven who they are.


From Microsoft's perspective, the login is valid.


That is exactly why device code phishing is so dangerous.


The attacker is operating within the trust model itself.


Hand typing on laptop with login screen showing Username and password fields and a lock icon in a dark, moody setting.

What SafeStorz Sees in Real Environments


One of the most common assumptions SafeStorz encounters during Microsoft 365 assessments is the belief that enabling MFA automatically closes the door on identity compromise.


In reality, identity security depends on multiple layers working together.


  • Conditional Access policies

  • Device compliance requirements

  • Identity governance

  • Threat detection

  • Session monitoring

  • Security baselines


Without those additional controls, businesses often develop blind spots they never realize exist.


This is one reason SafeStorz standardizes Microsoft 365 and Intune deployments rather than allowing every environment to evolve differently. Consistent Conditional Access policies, device compliance enforcement, and identity security controls reduce the opportunities attackers have to abuse authentication workflows.


Security should not depend on a single control doing all the work.


The FBI Recommendation: Restrict Device Code Authentication


Federal authorities are already responding to the rise of device code phishing.


One of the primary recommendations is to restrict or fully block device code authentication flows wherever possible through Microsoft Conditional Access policies.

For many organizations, that authentication method is rarely needed in daily operations.

Disabling unnecessary authentication pathways reduces the attack surface available to adversaries.


This is not a future recommendation.


It is something businesses should be evaluating right now.


And it is already part of the identity hardening approach SafeStorz implements for many Microsoft 365 environments.


The goal is not simply enabling security features.


The goal is understanding which features introduce risk and configuring them appropriately.


Why Detection Matters Just as Much as Prevention


Even properly configured environments can still face identity-based attacks.


That is why prevention alone is not enough.


Organizations also need visibility into suspicious behavior after authentication occurs.


This is where SafeStorz's layered security model becomes important.


Conditional Access policies help reduce exposure.


But if an attacker obtains a valid session token, additional detection capabilities become critical.


SafeStorz uses Cynet XDR with 24/7 MDR to identify behaviors that traditional authentication controls may miss, including:

  • Unusual login activity

  • Suspicious authentication patterns

  • Abnormal user behavior

  • Privilege escalation attempts

  • Lateral movement activity

  • Cloud-based attack indicators


The value is not simply the technology.


It is having security analysts actively monitoring and responding when suspicious activity occurs.


Because attackers do not always trigger alerts during initial access.


Often, the real indicators appear after they are already inside.


Why Infrastructure Architecture Still Matters


Identity security is increasingly becoming the primary battleground in cybersecurity.

But infrastructure design still matters.


A compromised Microsoft 365 account should not automatically provide access to every critical system inside an organization.


One reason SafeStorz emphasizes private cloud infrastructure, segmentation, and reduced blast radius architecture is because compromise should not dictate outcomes.

If an attacker gains access to an account, the environment should still limit what that account can reach.


Security is strongest when layers work together:


  • MFA

  • Conditional Access

  • Device compliance

  • Threat detection

  • Network segmentation

  • Private cloud isolation

  • Continuous monitoring


No single control is perfect.

Resilience comes from combining them.


The New Reality of Identity Security


The Kali365 campaigns highlight an important shift in cybersecurity. Attackers are no longer focused solely on stealing credentials.


They are increasingly focused on stealing trust.

The authentication process itself is becoming the target.


That means organizations need to move beyond the idea that checking the MFA box solves the problem.


MFA is still critical.


But it is only one piece of modern identity security.


SafeStorz helps organizations strengthen Microsoft 365 environments through Conditional Access hardening, Intune standardization, identity security reviews, Cynet MDR, and private cloud architectures designed to reduce risk when attackers inevitably adapt.


Because in 2026, the question is no longer whether you have MFA.


The question is what happens when an attacker finds a way around it.


Additional Reading


 
 
bottom of page