Skip to main content

Don’t fall for device code phishing

Device code phishing is where a phisher uses a legitimate security feature to access your accounts. By using legitimate log in screens from services like Microsoft, this clever scam can result in you handing over your details without knowing that anything is wrong. It’s intelligent, sophisticated and if you fall for it, it can be dangerous.

What is a device code?

A device code is a short string of numbers and letters which allows users to log in to their accounts on devices which might not use a keyboard; for example, an app for your television. It might take a long time to sign in using the on-screen keyboard, or users might not know their passwords. Instead, you can use a device code.

To use an app like Netflix or Disney on a new device, you have to tell the app you want to log in. When you select the sign in option on your TV, you’re requesting a device code. The TV then generates a device code and shows it on the screen. You can then use your phone to open the Netflix app or Disney app, or a webpage, and enter this code to approve the sign in. 

Then, you’re logged in to your Netflix or Disney account, on your television. You don’t usually have to approve a sign in option again; once you have approved the log in on your phone, your TV remembers it and keeps you signed in. Device codes can be useful, and are accessible ways of logging into your accounts. 

How are phishers using device codes?

In a device code phishing scam, instead of the user requesting the device code, the scammer does. The scammer tells a service or app that they are a device, and that they need a device code in order to sign in. The service provides that code. 

The phisher now needs a victim; a user that will take this device code, and approve it. The scammer sends a phishing email to you. In this email, there is a link to something which requires you to log in to an account, and the device code that the scammer has requested. The email will suggest that you need to input the code in order to access something like a secure webpage, or a PDF.

In the example we saw, the email had a link to a log in screen for Microsoft. This log in screen is legitimate; clicking the link really does take you to a Microsoft log in screen where you’re asked to input your details. However, the code that you’ve been asked to enter isn’t authorising you to access a secure webpage; it’s a device code that allows a device access to your account. And in this case, the device is a phisher.

The victim then enters the code, thinking that they’re gaining access to an important document or webpage. Instead, they’re giving permission to Microsoft to allow a phisher access to their account.

Don’t fall for fake device code requests

This scam is particularly dangerous, because device codes often provide continual access to an account. Here’s what you can do to ensure that you don’t fall for fake device code requests.

  1. Unless you requested the code, don’t use it

    Device code requests are meant to facilitate log-ins from a device that you’re looking at. Just like in the example with Netflix and your television, the code should have been requested by you.

    When someone sends you a code, and tells you to log in to something, be wary. Codes like these are meant to be requested by you, not requested by other people and then sent to you. Unless you requested the code, don’t use it.
  2. Read your webpages

    In the example we saw, Microsoft clearly states that once you enter the code displayed on your app or device, the device will have access to your account. It also gives a warning, ‘Do not enter code from sources you don’t trust’.

    It’s very easy to skim read these pages, but if you are asked to put in a code to gain access to something, the page you’re logging into should state this. It shouldn’t say that you’re allowing a device to access your account. In this case, all the information is in front of you.
  3. Check your sign-ins

    For apps which allow you to sign in on multiple devices, you can head to the Settings and see where you are signed in, and on which devices. If you see something suspicious, you can sign out from certain devices. This will usually be under ‘Sign in activity’ or ‘Devices’
  4. Send it to Junk

    Like with all phishing emails, the best way for you to keep yourself safe is ensuring that you don’t click any links in suspicious looking emails. If the graphics aren’t right, there are spelling mistakes, or you don’t recognise the sender, save yourself the stress and send it to Junk.

The Transcendit Way

Transcendit understand that when you choose to work with us, whether we're taking care of your IT, app or web development, you're trusting us with part of your business. So whether we're looking after your computers, phone systems or servers we always do things 'the Transcendit way'.

The whole of our team adhere to the same values, beliefs and policies - the principles that were written when Transcendit first formed in 2000. Whether you come to us for cloud services or recovery backup you can be confident that you'll always receive the same excellent service.

The Transcendit way outlines how we do business; following the same straightforward principles with every client and customer, regardless of how big or small they may be.

That means we get to know you and your business. We offer you a friendly, professional and efficient service, and we'll always be honest with you.
We understand that not everybody speaks fluent IT, so we try to explain things in a way that is simple and clear. We always spend as much time as is necessary explaining things to you.
If you need to talk to us about something, no matter how insignificant, we are only ever a phone call away – and we’re never too busy to make you a cup of tea and have a sit down with you in person.
We understand how frustrating it can be when things are late. When we schedule an appointment with you, we are there when you’re expecting us. If something prevents us from getting there, we always call you in advance to let you know.
Sometimes things can go wrong, but we never lie to you or try to cover something up. If things go askew we tell you what’s happened and how we plan to prevent it affecting your business.
We want you to continuously benefit from working with us. We regularly discuss your business and make suggestions for improving systems and processes wherever we can – but we never try to push you into a purchase.
When we quote a fixed price, that's always the amount we charge – you won’t find any nasty surprises on a bill from us. If you are paying by time and materials, we inform you if our approximations could change.
We understand the importance of privacy for your business and your customers. We respect the confidentiality of your data, and we will never pass on your information to third parties.
We appreciate it when you take the time to give us feedback. A system called CustomerSure records our client's responses, so you can trust that our reviews are from real people.
Find out what they're saying here .
Ivo was very helpful, efficient and easy to talk to. Georgina

Based on 13148 reviews our customers rate us 9.8/10. Reviews and ratings by Customersure. 07-November-2025

Transcendit are proud sponsors of CHUF, the Children's Heart Unit Fund.

Transcendit is a Living Wage employer
Transcendit is a Microsoft Solutions Partner
Vipre partner
IPCortex partner
WithSecure partner
DELL partner
Barracuda partner
Veeam partner
N-Able partner
Huntress partner