Microsoft 365 & Email Security

A Real Microsoft Login Can Still Expose Your Business Email

Learn how Microsoft 365 device code phishing can expose business email, with agriculture and trucking examples, staff warning signs, and practical IT checks.

A genuine Microsoft sign-in page can still approve an attacker's access. Here is what owners and office managers should check now.

How Microsoft 365 device code phishing works

A supplier sends a document. A broker shares a file. An employee follows the instructions, checks that the sign-in page belongs to Microsoft, and enters the code provided.

The page is real. The access request may belong to an attacker.

That is the trick behind Microsoft 365 device code phishing. On September 22, 2026, Microsoft described EvilTokens campaigns that compromised more than 12,000 inboxes across over 10,000 organizations worldwide. Those figures cover multiple industries; they are not agriculture- or transportation-specific counts.

For a business that coordinates orders, deliveries, or payments by email, unauthorized mailbox access can put trusted relationships at risk.

Device-code sign-in is legitimate. It lets someone sign in on equipment with limited input options by entering a short code in a browser on another device. The problem is that an attacker can start the request and talk an employee into approving it. The attacker may never need the password.

Agriculture email security: a supplier document can become an access request

Consider this illustrative scenario: an agricultural retailer receives a message about a revised fertilizer order. The linked page asks an employee to enter a Microsoft code to view the document. With deliveries approaching, the employee treats the step as routine verification.

If that approval grants mailbox access, an attacker could learn supplier names, purchasing patterns, invoice details, and the timing of upcoming payments. That context could support a more convincing request to change bank information.

The same concern applies to feed dealers, farm-service businesses, grain businesses, and smaller cooperatives. During a busy ordering or harvest period, a short pause to verify an unexpected access request belongs in the workflow.

Transportation and logistics: protect the inbox behind the shipment

A second illustrative scenario: a dispatcher receives what appears to be a broker's updated rate confirmation. The message directs the dispatcher to copy a code and sign in with Microsoft before viewing the file.

Mailbox access could expose customer conversations, shipment details, invoices, or factoring correspondence. An impersonator could use that information to make a later payment or document request appear relevant to a real load.

A compromised Microsoft 365 inbox does not automatically establish access to a transportation management system or load board. The immediate concern is the information and trusted communications available through that account. This is an illustrative scenario, not a reported EvilTokens incident at a carrier.

Five checks for business owners and IT providers

Assign these checks to a person. They are small process changes, not a new security program:

  1. Warn staff about the exact situation: an unexpected request to copy a code into a Microsoft page to view an invoice, order, or shipment document. Tell them to stop and verify the request through a known contact method. The key question is: “Did I start this sign-in, and do I recognize the application or device?”
  2. Ask your Microsoft 365 administrator whether device-code authentication is needed. Microsoft recommends blocking the flow as much as possible and keeping only documented exceptions. Test the Conditional Access change in report-only mode first, then confirm licensing, dependencies, and exceptions before enforcement.
  3. Ask for evidence, not a verbal assurance. Request the policy scope, enforcement status, exception list, and date of the last review. A report-only policy records activity; it does not block it.
  4. Keep payment verification outside email. Confirm new bank details or payment instructions using a known phone number or established channel. This applies to supplier and equipment payments in agriculture and carrier, broker, and factoring changes in transportation.
  5. Make reporting easy. Tell office, purchasing, dispatch, and accounting staff exactly whom to call if they entered a suspicious code. Encourage immediate reporting, even when they are unsure anything happened.

What if an employee already entered a code?

Contact your administrator or security provider immediately through a known channel. Preserve the message, approximate time, and details of what was approved.

A password reset alone is not enough. Microsoft's response guidance includes containing access, revoking sessions, checking authentication methods and application permissions, reviewing forwarding and inbox rules, and investigating sign-in and audit records.

If the affected account handles payments, have the responsible team independently check recent changes while the technical investigation proceeds.

Verify the safeguards your business depends on

The useful question is not simply whether your company has Microsoft 365 or MFA. It is whether the relevant protections are configured, enforced, and supported by evidence.

Securing Your Business provides a Business Security Baseline to review agreed safeguards, including Microsoft 365 identity and access protections, and identify priorities for leadership and your IT provider.

Ask to include device code authentication and relevant sign-in policies in the agreed assessment scope. Internal verification requires authorized access and evidence; a public exposure review cannot establish whether these controls are working.

Verify the Microsoft 365 safeguards your business depends on.

The $1,995 Business Security Baseline reviews agreed internal safeguards and available evidence, including Microsoft 365 identity and access protections. The free Zero-Access Business Exposure Review is different: it checks public signals without passwords or internal access.

See the Business Security BaselineStart the free exposure review