A convincing phishing email, a device-code attack that slips past MFA, and the four-minute window that decided the outcome.
A long-standing client of Cloud Systems narrowly avoided a costly Microsoft 365 account compromise when an employee clicked a malicious link buried inside what looked like a legitimate email from her law firm. The attack used a device-code phishing technique specifically designed to bypass multi-factor authentication. Because the client's environment was under continuous, real-time monitoring, the intrusion was detected, contained, and reversed before the attacker could touch a single email or document.

An employee received what appeared to be a forwarded message from her law firm: correct letterhead, real reference numbers, and a standard confidentiality footer attached to a representation agreement. Nothing about the email looked out of place.
The one anomaly was a link embedded inside the attached document. When she clicked it, the link triggered a device-code attack, a phishing technique that tricks a user into authorizing a new device on their account. Because the user completes the authorization step herself, this method quietly slips past standard MFA protections. The attacker then registered a rogue device, designed to blend in as trusted hardware inside the Microsoft 365 tenant.
Cloud Systems' monitoring detected the anomalous sign-in and device registration activity within moments of it occurring. The response was immediate and automated:
The compromised account was locked.
Active sessions tied to the attacker were killed.
The rogue device was identified and removed from the tenant.
Just as important as the technology was the human response. Once locked out, the employee called Cloud Systems immediately and reported that she had clicked something suspicious, no hesitation, no attempt to see if it would “blow over.” That prompt, honest report, combined with the detailed activity logs already captured by the monitoring tools, let the team confirm the root cause within minutes rather than spending hours reconstructing the incident after the fact.


From the moment the link was clicked to the moment the account, sessions, and rogue device were fully contained, the attacker had roughly four minutes of access, and used none of it. No emails were read. No documents were accessed or exfiltrated. An incident that could have led to significant financial loss, data exposure, or business disruption was closed out as a non-event.
The attack was caught because the environment was being watched in real time, not reviewed after the fact. Device-code phishing is built to slip past MFA quietly; catching it requires visibility into sign-in and device activity as it happens.
The employee's immediate, honest report was just as critical as the technical detection. It collapsed the investigation from hours to minutes and is a large part of why the incident never escalated.
The incident is a reminder that a password plus MFA is no longer a complete defense on its own. Modern phishing techniques are specifically designed to work around it, which is why active monitoring and rapid response have become essential layers.
Convincing paperwork from a trusted name is exactly how modern phishing works — a link inside a document always deserves a second look.
MFA alone doesn't stop device-code phishing attacks; real-time monitoring and fast response do.
When someone clicks something they shouldn't have, speed of disclosure beats blame every time — and it can be the difference between a non-event and a costly breach.
This is what continuous monitoring and a fast, human response looks like in practice. If you're not sure how quickly your current provider would catch this, let's talk.

© Copyright 2026. All rights reserved.