Device Code Phishing in 2026: How EvilTokens Bypasses MFA and Hijacks Microsoft 365 Accounts
In four weeks of 2026, attackers fired 7 million device code phishing attempts at Microsoft 365 users β bypassing MFA without ever asking for a password. Here is how the EvilTokens kit works, why standard 2FA does not stop it, and the five concrete defenses every M365 user should apply this week.