A B2B Software Company Shuts Down a Device Code Phishing Attack in Microsoft 365

Get a Quote
The Project

Overview

A B2B software company called BD Emerson when attackers used device code phishing to take over Microsoft 365 accounts. We revoked the stolen tokens, blocked the device code flow across the tenant, mapped the blast radius, and handed a documented incident to the forensics firm.
Partnership

BD Emerson x 

Device Code Phishing Incident Response for a B2B Software Company

The client and the problem

Employees at a B2B software company received what looked like a Microsoft Teams voicemail notification. The link ran through a legitimate file-sharing service to an attacker's page, which walked each victim through Microsoft's device code sign-in, the flow built for devices without keyboards. Victims entered a code on a real Microsoft page and completed their own MFA, and the attacker received valid tokens for their accounts without ever knowing a password. When the company called us, several accounts were compromised and phishing email was going out from them to customers and partners.

What we did

Containment came first. We revoked refresh tokens for every affected account, because a password reset alone leaves a stolen token working, and reset credentials programmatically through Microsoft Graph so no account was missed. We blocked the device code authentication flow across the tenant with a Conditional Access policy. Then we mapped the blast radius: which accounts had authenticated through device code, what the attacker did with each one, and which phishing messages were still sitting in inboxes, which we removed. One workstation turned up unauthorized remote access software, and it went into the forensic scope.

How the incident widened

The scope grew as the logs came in. The count of compromised accounts rose from six to nine, three of them shared mailboxes that no single person watched. The phishing had reached hundreds of external domains, nearly double the company's first estimate, and the earliest suspicious activity pointed to access that had gone unnoticed for months.

The result

The device code path the attacker used is closed across the tenant, and the stolen tokens no longer work. Leadership received an incident report it could act on, along with guidance on activating its cyber insurance, engaging counsel to direct the forensic work, and assessing breach notification thresholds. BD Emerson served as the tourniquet: we stopped the bleeding, preserved the evidence, and handed a documented incident to the insurer's panel forensics firm for the full investigation.

Why the client is not named

Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. Response work like this runs through our cyber incident response team, and a Microsoft 365 security assessment finds the same exposures before an attacker does. Companies that want responders lined up in advance use our incident response retainer. We are glad to walk through comparable work under NDA.

Industry
Software
Location
United States
Company size
Mid-market
Founded
Undisclosed
CONTACT

Seeing sign-ins you cannot explain?

Get a Quote

We contain first, preserve the evidence, and hand forensics a clean record. Book a working session before the next incident starts.

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.