What is a device-code phishing attack?

Updated View source
Stay safe

A device-code phishing attack tricks you into approving a sign-in code on your real account, which signs the attacker in as you without your password.

The feature it abuses

Some devices are hard to type on: a smart TV, a game console, a printer. To sign in, they show a short code for you to enter on a web page on your phone, then approve. The attacker starts that sign-in on their own device, gets the code, and sends it to you. Enter it and approve, and the access lands on their device.

How the attack works

Four steps of a device-code scam 1 A message arrives with a code WDJB-MFQK 2 You open the real microsoft.com/link and sign in 3 You type the code and approve it 4 The attacker's device is now signed in as you
The page is real, the code is theirs.

Why it fools careful people

The usual advice says check the address. Here the address is real, microsoft.com or google.com. The trick lives in the message: a time limit, because the code expires in minutes, and routine wording. Verify, confirm, activate.

How to protect yourself

One rule covers it: only enter a device code that you started yourself, on a device in front of you right now.

Fish Catcher warns you in plain language when a page walks you through a device code in a setting that looks like a scam. It never blocks the page.

Common questions

How is this different from normal phishing?

Normal phishing sends you to a fake website. This sends you to the real one, and the code you approve signs in the attacker's device.

Does two-factor authentication stop this attack?

Not on its own. You complete the two-factor step yourself, and the attacker's device inherits the approved session.

What should I do if I already entered a code?

Sign out of all sessions, change your password, and check connected devices. For a work account, tell your IT team right away.