Device-Code Phishing

    A Real Sign-In Page, the Wrong Person

    Someone asks you to enter a code on a genuine sign-in page. Doing so can sign them into your account.

    Everyday Cyber SafetyEveryday usersIT & help deskLeadership

    Illustrative scenario

    How It Looks in Real Life

    A contact invites you to a meeting and says: “Go to the official Microsoft device login page and enter code ABCD-1234 to join.” The page is real.

    Understand it

    How the Attack Works

    Device-code sign-in lets devices without keyboards, such as TVs, sign in using a code entered elsewhere. Attackers start that flow themselves and send you the code. When you enter it, their device receives access to your account.

    Red flags

    Warning Signs

    • Anyone other than a device in front of you supplying a sign-in code.
    • Codes sent through chat, email or messaging apps to “join a meeting” or “verify”.
    • A prompt saying you are signing in on a device you do not have.

    Safer habits

    What to Do Instead

    • 1Only enter device codes shown on a device you are personally setting up.
    • 2Remember that a genuine authentication domain does not prove the requester is trustworthy.
    • 3Report unexpected code requests to IT.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: approved app permissions or a sign-in request
    1. 1Report it straight away so IT can revoke the session or app consent.
    2. 2Remove the unfamiliar app from your account’s connected apps or permissions page.
    3. 3Changing your password does not remove app permissions or tokens already issued.
    If you: entered credentials or shared a code
    1. 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
    2. 2Change the password from a trusted device by typing the real address yourself.
    3. 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
    4. 4Review recovery email, phone number and forwarding rules for unexpected changes.

    Knowledge Check

    What Would You Do?

    A new “partner” sends a code and asks you to enter it on the official sign-in page to access a shared file. Safe choice?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us