Security Advisory
An active phishing campaign, tracked as EvilTokens, is abusing Microsoft's device sign-in flow to hijack Microsoft 365 accounts. Attackers send a code by email or message and ask the recipient to enter it at microsoft.com/devicelogin, which lets the attacker capture a valid session even after multifactor authentication (MFA) is completed.
Action required: Do not enter a device code you received in an email or message unless you started the sign-in yourself.
Advisory details
| Article type |
Security Advisory |
| Audience |
Students and employees |
| Severity |
High |
| Status |
Active |
| Last updated |
August 12, 2026 |
Summary
The California Community Colleges Security Center has notified member colleges of an active phishing campaign, known as EvilTokens, that targets Microsoft 365 accounts by abusing Microsoft's legitimate device sign-in process. Because the victim signs in on a real Microsoft page and completes MFA, the activity can look legitimate while the attacker captures an access token and keeps access to the account without ever learning the password.
The attack typically starts with an email claiming that a document, encrypted message, or other resource is waiting. The message tells the recipient to visit Microsoft's device login page and enter a code the attacker supplies. When the user signs in with their District Microsoft 365 account and completes MFA, the attacker's session is authorized instead of a legitimate device.
Who is affected?
Any District Microsoft 365 account holder, including faculty, staff, and students, may be targeted. Accounts with mailbox access, shared drives, or elevated permissions are especially attractive to attackers.
If you are not part of the affected group, no action is required unless otherwise stated below.
What you need to do
Take the following steps whenever you receive a message that involves a Microsoft sign-in code:
- Do not enter a device code at microsoft.com/devicelogin unless you started the sign-in yourself on a device you control.
- Do not approve a Microsoft Authenticator prompt, phone call, or SMS message that you did not trigger.
- Report the suspicious message using the District's Information Security Incident form.
What to watch for
Be alert for:
- Any message that tells you to visit microsoft.com/devicelogin and enter a code.
- Claims that a document, voicemail, fax, or encrypted or secure message can only be opened by completing a device sign-in.
- Urgency or pressure to complete a sign-in quickly.
- Messages that appear to come from a trusted contact but include an unusual request. Attackers often send device code lures from previously compromised accounts.
Do not enter a device code, approve an MFA prompt, or forward the message to colleagues.
What Technology Services is doing
Technology Services is:
- Monitoring District Microsoft 365 sign-in activity for signs of device code abuse.
- Implemented Microsoft 365 authentication and conditional access controls to reduce exposure to this technique.
- Coordinating with the California Community Colleges Security Center on indicators and guidance.
- Revoking tokens and resetting credentials for any account confirmed or suspected to be compromised.
Reporting concerns
If you entered a device code, approved an unexpected sign-in prompt, or believe your account may be affected:
- Stop interacting with the suspicious message or sign-in prompt.
- Change your District Microsoft 365 password from a trusted device.
- Report an Information Security Incident as soon as possible.
- Include the sender address, date and time, a screenshot of the message if available, and the name of any device where you entered the code.
Protect sensitive information: Do not include passwords, verification codes, recovery codes, tokens, or other secrets in a service request.
Additional information
Device code phishing has become a common technique for gaining persistent access to Microsoft 365 accounts because it bypasses password theft and can survive MFA. Continue to use MFA on all District systems, keep your recovery methods current, and treat any unsolicited sign-in code as suspicious until verified through a separate channel.