Device code phishing exploits the OAuth 2.0 Device Authorization Grant by tricking victims into entering a legitimate short code on a real sign-in page, unknowingly approving a scammer's sign-in request and granting them access to the victim’s account. This attack bypasses typical security measures such as multifactor authentication because the victim themselves authorizes the sign-in, allowing attackers to obtain authentication tokens to access emails, files, or other services depending on granted permissions. Users should be wary of unexpected requests to enter sign-in codes purportedly for meetings or documents and verify legitimate device sign-ins, while monitoring account activity if a scam is suspected.
How Device Code Phishing Gives Scammers Access to Your Account

