How Does This Microsoft Scam Actually Work?
Kaspersky researchers have identified a phishing campaign targeting corporate employees in Brazil that hijacks Microsoft accounts without ever stealing a password. The attack exploits a legitimate Microsoft feature used to link new devices to a corporate account.
What Happens Step by Step?
The attack begins with a phishing email carrying an urgent subject line β such as a pending quote or purchase order. The message contains a PDF or a link hosted on a legitimate website, used only as a relay to redirect the victim to a fake page created by the criminals.
On that page, a notice warns that the document is protected and that viewing it requires a validation code β displayed right on the screen. The victim believes the number simply unlocks the PDF.
How Is the Account Taken Over?
While the victim is on the fake page, the criminal simultaneously initiates a legitimate Microsoft device-linking request in the background. Microsoft automatically generates an authorisation code for that request β and that is exactly the code displayed to the victim on the fake page. When the employee types it into the official Microsoft login page, they unknowingly authorise a stranger's device to connect to their own corporate account.
Kaspersky's lead security researcher Fabio Marenghi warns that the campaign's main risk lies in exploiting user goodwill through a convenience feature common in corporate environments, normally used to validate access to work apps via code.
What Should Employees Do to Stay Safe?
- Refuse any request to authorise a new device if you did not personally initiate a login at that moment.
- Legitimate documents β invoices, bank statements β never require a validation code to be viewed.
- Report suspicious emails to your IT or security team immediately.
- Enable conditional access policies and monitor linked devices in your Microsoft account settings.
- Scam identified by Kaspersky and detailed on Securelist.com.
- No password is stolen β the victim authorises access themselves.
- Attackers gain control of email, SharePoint files and Teams conversations.
- The fake page displays a real Microsoft authorisation code generated in the background.
- Lead researcher: Fabio Marenghi, Kaspersky Brazil.
π¬ Comments
Sign in to comment and like