Security Stop-Press: Cybercriminals Bypassing MFA With Device Code Phishing

Microsoft has reported uncovering a cyberattack campaign by Storm-2372, a group linked to Russian interests, using a technique called device code phishing to bypass multi-factor authentication (MFA) and steal access tokens.

Active since August 2024, the group targets governments, NGOs, and industries including defence, telecoms, energy, and healthcare across Europe, North America, Africa, and the Middle East. In device code phishing, attackers trick users into entering a legitimate authentication code, sent via fake meeting invites on platforms like Microsoft Teams and WhatsApp, on a genuine sign-in page. This hands over valid tokens, granting unauthorised access.

Recent activity shows a shift towards using Microsoft Authentication Broker’s client ID to gain persistent access by registering rogue devices inside compromised networks. Microsoft warns these attacks are especially effective because they mimic legitimate login workflows.

To defend against device code phishing, businesses should block unnecessary device code flows, strengthen Conditional Access policies, educate users about phishing risks, and use phishing-resistant MFA methods such as FIDO tokens.

Security Stop Press : Google Cloud to Enforce Mandatory MFA for All Users by 2025

Google has announced a phased rollout of mandatory multi-factor authentication (MFA) for all Google Cloud accounts to strengthen security against cyber threats.

Starting in November 2024, Google Cloud will encourage MFA adoption, progressing to full compliance by the end of 2025. Google says the move will occur in three stages: first, promoting MFA awareness; next, requiring MFA for all password-based logins by early 2025; and finally, extending this to federated users by year-end, who can use MFA via their identity provider or add an extra layer through Google.

The decision is in response to rising risks from phishing and credential theft. Google and the Cybersecurity and Infrastructure Security Agency (CISA) report that MFA reduces hacking risk by 99 per cent. Google, an early advocate of MFA, continues to prioritise secure, user-friendly options like passkeys that leverage biometrics.

Businesses using Google Cloud are advised to start planning for MFA deployment now, coordinating with users and IT teams to facilitate a smooth transition.