A message about a year-end bonus may send an employee to Microsoft's real sign-in page. The page can be genuine while the sign-in request belongs to someone else.
What Microsoft reported—and what it did not
A message says a holiday bonus statement is ready. It asks an employee to copy a short code, open Microsoft, and sign in. The sign-in page may be real, but entering an unexpected code can authorize a session the employee did not start.
Microsoft's September 22, 2026 research described EvilTokens, a phishing service used in campaigns that compromised more than 12,000 inboxes across over 10,000 organizations worldwide. Microsoft reported lures involving compensation and benefits, shared files, invoices, and other business themes.
Microsoft did not report a specific Christmas-bonus campaign. A bonus notice is a plausible seasonal version of the compensation lures it described—not a claim about a confirmed holiday campaign.
How a sign-in code can approve the wrong session
Device-code sign-in is a legitimate Microsoft feature. It lets someone sign in on a device with limited input by entering a code in a browser on another device. In a phishing attempt, the attacker—not the employee—starts the sign-in.
A real Microsoft address confirms where the sign-in is happening; it does not confirm who started it.
- The attacker receives a temporary code for a session they control.
- A message asks the employee to enter that code on Microsoft's real sign-in page.
- If the employee completes the request, Microsoft authorizes the attacker's session. The attacker may not need the employee's password.
What to tell staff about year-end messages
Bonus and benefits messages are only two possible lures. A shared holiday schedule or year-end document can create the same problem if it asks someone to enter a code they did not request.
- For a bonus or benefits notice, open the usual payroll or HR portal yourself. Check with the person who handles payroll using contact details you already have.
- For a shared schedule or document, go to the familiar SharePoint, Teams, or scheduling location, or confirm with the sender through a separate channel.
- If any message tells you to copy a sign-in code, pause. Only continue if you personally started that sign-in on a device or app you recognize.
Questions to ask your IT provider
Ask your Microsoft 365 administrator to explain whether device-code sign-in is needed and how it is controlled. Microsoft recommends blocking the authentication flow where possible and limiting exceptions to documented needs.
- Which users, devices, or applications need device-code sign-in?
- If the business does not need it, is a Conditional Access policy set to block it? Has the policy been tested in report-only mode before enforcement?
- If there are exceptions, which accounts are covered, why are they needed, and when were they last reviewed?
- Who should an employee contact right away after approving a sign-in they did not start?
- Do not enforce a new identity policy without checking device dependencies and emergency access. The Business Security Baseline reviews agreed internal safeguards; the free Zero-Access Business Exposure Review checks public signals and does not verify internal settings.
If someone entered a code or approved a request
Contact your Microsoft 365 administrator or IT provider immediately through a known channel. Preserve the message and note when the code was entered or the request was approved. The responder should review sign-in activity, registered devices and authentication methods, connected applications, and mailbox forwarding or inbox rules. A password reset alone may not end every active session.
If the account handles payments or sensitive correspondence, check for suspicious messages and changes while the technical investigation is underway. Follow your incident-response and insurance-notification procedures. An unexpected code approval warrants investigation, but it does not by itself prove that data was stolen.
How we can help
Security Awareness Training gives employees a short scenario each week and feedback on safer responses. Managed Phishing Testing & Staff Training is a separate service: we run authorized email simulations and provide follow-up training and a dated report.
To check the protections behind Microsoft 365 sign-ins, the $1,995 Business Security Baseline reviews agreed internal safeguards and evidence, including sign-in and administrator controls. It is for businesses with up to 25 employees and is not incident forensics or automatic remediation. If you suspect an account is currently compromised, contact your Microsoft 365 administrator or IT provider first. The free Zero-Access Business Exposure Review checks public signals; it does not verify internal account settings.
Related resources
Give staff a chance to practice before the next suspicious message
Weekly scenarios help employees rehearse how to recognize and report suspicious sign-in requests.
