What is a device-code phishing attack?
A device-code phishing attack tricks you into approving a sign-in code on your real account, which signs the attacker in as you without your password.
The feature it abuses
Some devices are hard to type on: a smart TV, a game console, a printer. To sign in, they show a short code for you to enter on a web page on your phone, then approve. The attacker starts that sign-in on their own device, gets the code, and sends it to you. Enter it and approve, and the access lands on their device.
How the attack works
- The attacker starts a device login and gets a code like WDJB-MFQK.
- They message you, posing as IT or a service you use, and ask you to enter the code on the real sign-in page to "verify your account".
- You open the real page, sign in, and approve. Nothing looks wrong, because nothing is fake.
- The attacker's device is now signed in as you, often for a long time.
Why it fools careful people
The usual advice says check the address. Here the address is real, microsoft.com or google.com. The trick lives in the message: a time limit, because the code expires in minutes, and routine wording. Verify, confirm, activate.
How to protect yourself
One rule covers it: only enter a device code that you started yourself, on a device in front of you right now.
- A code that arrives by email, text, or chat, asking to be typed into a sign-in page, is a scam.
- Ask yourself: did I just try to sign in a TV, console, or app? If not, do not enter the code.
- "Enter this in the next five minutes or lose access" is pressure, not a deadline.
- If the message claims to come from IT, check through a channel you already trust.
Fish Catcher warns you in plain language when a page walks you through a device code in a setting that looks like a scam. It never blocks the page.
Common questions
How is this different from normal phishing?
Normal phishing sends you to a fake website. This sends you to the real one, and the code you approve signs in the attacker's device.
Does two-factor authentication stop this attack?
Not on its own. You complete the two-factor step yourself, and the attacker's device inherits the approved session.
What should I do if I already entered a code?
Sign out of all sessions, change your password, and check connected devices. For a work account, tell your IT team right away.