
Employees at a B2B software company received what looked like a Microsoft Teams voicemail notification. The link ran through a legitimate file-sharing service to an attacker's page, which walked each victim through Microsoft's device code sign-in, the flow built for devices without keyboards. Victims entered a code on a real Microsoft page and completed their own MFA, and the attacker received valid tokens for their accounts without ever knowing a password. When the company called us, several accounts were compromised and phishing email was going out from them to customers and partners.
Containment came first. We revoked refresh tokens for every affected account, because a password reset alone leaves a stolen token working, and reset credentials programmatically through Microsoft Graph so no account was missed. We blocked the device code authentication flow across the tenant with a Conditional Access policy. Then we mapped the blast radius: which accounts had authenticated through device code, what the attacker did with each one, and which phishing messages were still sitting in inboxes, which we removed. One workstation turned up unauthorized remote access software, and it went into the forensic scope.
The scope grew as the logs came in. The count of compromised accounts rose from six to nine, three of them shared mailboxes that no single person watched. The phishing had reached hundreds of external domains, nearly double the company's first estimate, and the earliest suspicious activity pointed to access that had gone unnoticed for months.
The device code path the attacker used is closed across the tenant, and the stolen tokens no longer work. Leadership received an incident report it could act on, along with guidance on activating its cyber insurance, engaging counsel to direct the forensic work, and assessing breach notification thresholds. BD Emerson served as the tourniquet: we stopped the bleeding, preserved the evidence, and handed a documented incident to the insurer's panel forensics firm for the full investigation.
Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. Response work like this runs through our cyber incident response team, and a Microsoft 365 security assessment finds the same exposures before an attacker does. Companies that want responders lined up in advance use our incident response retainer. We are glad to walk through comparable work under NDA.