New phishing attacks target the device code authentication method, bypassing multi-factor protection to steal access credentials.
Cybercriminals operating the Greatness phishing-as-a-service platform have discovered a fresh method to break into accounts protected by multi-factor authentication (MFA). Instead of attacking the traditional username-and-password combination, they're now exploiting a lesser-known login feature called device codes—essentially creating a backdoor around security systems that millions of people depend on.
Think of MFA like a two-lock security system on your front door. You need both your key (password) and a security code from your phone to enter. This new attack bypasses the second lock entirely by tricking users into handing over a special temporary code designed for logging into devices, like when you connect a smartphone to your smart TV.
Device codes work by allowing people to authenticate from devices that don't have keyboards easily accessible—like game consoles or smart speakers. A user gets a short code, visits a website on their computer, enters that code, and suddenly their TV is connected to their account. It's convenient and legitimate.
What makes this dangerous is that attackers are now impersonating legitimate services and convincing people to give them these codes through phishing messages. Once criminals obtain the code, they can use it to access a target's account, steal authentication tokens (the digital keys that keep you logged in), and maintain access long after the user changes their password.
The Greatness service makes launching these attacks disturbingly simple. It's a ready-made toolkit that criminals rent to conduct phishing campaigns at scale, handling everything from fake login pages to message delivery.
This represents a meaningful shift in how attackers think about breaking in. Rather than directly confronting advanced security measures, they're finding the gaps in less-monitored systems. Device code authentication hasn't received the same attention as traditional MFA methods, leaving many organizations and individuals unaware of the risks.
For businesses, this means employees could unknowingly compromise enterprise accounts. For personal users, your email, cloud storage, and social media accounts become vulnerable—especially if you reuse the same login across platforms.
The real danger: Once attackers steal your authentication tokens, they can stay inside your account invisibly, even after you change your password or enable MFA elsewhere.
IT teams need to monitor device code authentication logs for suspicious activity and consider restricting device code flows for sensitive user accounts. Security awareness training should specifically mention this threat.
As attackers become more creative about bypassing protections, staying informed and cautious about unexpected authentication requests remains your strongest defense.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →