It came from someone I knew. So I clicked.
The email asked me to review a proposal. It came from her real account, the request fit the relationship, and my first thought was that our security filter was being too cautious. INKY blocked the link before the page loaded, so I called her. She had not sent it, and her account had already been compromised.
Why I Clicked It
This was not the sloppy, misspelled phishing email everyone is trained to expect. It looked like a normal piece of business from someone I already trusted.
I have seen plenty of obvious phishing emails. The logo looks wrong, the sender address has one strange letter, or the message is written like nobody in the real world talks. This was different.
I knew the sender. A proposal was believable. The email was not asking for a wire transfer or threatening to close an account in ten minutes. It looked like a normal piece of business.
The uncomfortable part is that I did not stop because my instincts caught it. I stopped because a security tool would not let me keep going. That is an important difference.
✓What made it believable
- It came from the sender's real account.
- The request fit a normal business conversation.
- There was no wild promise or obvious threat.
- The message used trust that already existed.
!What changed the outcome
- The link was checked before the page loaded.
- The block created a reason to slow down.
- I verified the request outside the email thread.
- The sender confirmed the account was compromised.
How a Microsoft 365 Phishing Attack Can Come From a Real Account
Once an attacker has access to a real mailbox, the address people trust becomes the delivery system for the next message.
Most phishing advice starts with checking the sender. That still matters, but it does not solve this version of the problem. Once an attacker has access to a real mailbox, they can send messages from the address people already trust.
They may also see old conversations, contact names, invoices, project language, and normal writing patterns. They do not need to guess who the person works with because the mailbox can show them.
That is how one mistake can spread. The first person enters information. Their account becomes the next delivery system. Then a customer, coworker, or vendor sees the familiar name and gives the message more trust than it deserves.
This is often described as business email compromise. The technical details can vary, but the business problem is simple: the attacker is borrowing a real identity to make the next lie easier to believe. It is one of the main reasons layered managed security matters, because the fix is not a single tool, it is a set of protections working together.
What the Copied Code May Be Doing
The instructions we heard match a known method called device code phishing, but the blocked page means I cannot claim with certainty that this was the exact method used.
I never reached the page because the link was blocked, so I cannot say with certainty which exact method this specific attack used. The instruction to copy a code, avoid the normal Authenticator process, and continue through Microsoft matches a known pattern called device code phishing.
Device code sign-in is a real Microsoft feature used for devices that are awkward to sign into directly, such as smart TVs, printers, and some shared meeting-room systems. The attacker can start that sign-in process on a device they control, then convince the victim to enter the code and complete the login. Restricting sign-in methods a business does not use is the kind of setting our managed IT support reviews and locks down before it becomes a problem.
The steps look like document access, so the sign-in feels connected to the file.
The Microsoft page can be real. The lie is what the person has been told they are approving.
Microsoft describes device code flow as a high-risk authentication method that can be used in phishing and recommends blocking it where a business does not need it. You can read the Microsoft guidance on device code flow for the technical explanation.
Why the Email Security Layer Mattered More Than My Gut
The block did not make me smarter. It created enough friction to stop a normal click from becoming the next step in the attack.
I do not think the answer is to expect every employee to become a security analyst. People are moving fast, answering customers, reviewing documents, and trying to finish the work in front of them. A believable email will eventually catch someone at the wrong moment.
Training still matters. People should know not to paste an unexpected code into a login page, approve a sign-in they did not start, or trust a message only because the sender is familiar. But training cannot be the only layer.
Stop what you can
Check links, attachments, and destinations before the employee reaches the page.
Limit what gets approved
Use stronger login controls and restrict sign-in methods the business does not need.
Respond fast
Watch for unusual activity and know how to contain an account when someone reports a mistake.
In this case, email security checked the destination and stopped the page before I could make the next mistake. A stronger managed security setup should combine that kind of email protection with login controls, device monitoring, alerts, and a response process for when something still gets through.
AI will make the old “look for bad grammar” advice less useful over time. It is easier than ever to clean up wording and make a message sound normal. The protections behind the employee have to improve too. If something does slip through, monitored managed backup is what gives the business a clean way back.
What to Do If Someone Entered Their Information or the Code
Do not wait to see whether anything happens. Speed matters, but so does doing more than changing the password.
A compromised email account can be used to send more messages, hide replies, review financial conversations, or create access that survives a basic password change.
Immediate response checklist
Act fast- Call your IT or security team and explain exactly what was entered, approved, or downloaded.
- Block the account from new sign-ins while the incident is being reviewed.
- Revoke active sessions and refresh tokens, not only the password.
- Reset the password and review registered MFA methods and devices.
- Check recent sign-ins, sent mail, forwarding settings, and inbox rules.
- Warn anyone who received a suspicious message from the compromised account.
- Review invoice, payment, and banking conversations for changes or impersonation.
A good response is not about blaming the person who clicked. You need the truth quickly. If employees think they will get embarrassed or punished, they are more likely to stay quiet, and that lost time gives the attacker more room.
If your business does not have a clear plan for the steps above, that is exactly the gap our managed security and cybersecurity services are built to close, so a mistake becomes a quick phone call instead of a company-wide incident.
What Businesses Should Have in Place Before This Happens
The goal is not to pretend nobody will ever click. The goal is to make sure one believable email does not become a company-wide problem.
- Email link and attachment protection: Check destinations before and after delivery, including links sent from otherwise trusted accounts.
- Stronger sign-in controls: Use MFA, move toward phishing-resistant methods where practical, and restrict device code flow when the business does not need it.
- Cloud and account monitoring: Watch for unusual sign-ins, new forwarding rules, unexpected MFA changes, and suspicious Microsoft 365 activity.
- Fast incident response: Make sure someone knows how to lock an account, revoke sessions, inspect the mailbox, and contact affected people.
- Tested recovery: If phishing leads to ransomware or data loss, monitored managed backup gives the business a way back.
- Useful employee training: Use real examples like proposals, shared files, invoices, and login codes instead of a once-a-year slideshow nobody remembers.
For businesses that want these pieces handled together, our cybersecurity services and managed IT support are built around the same idea: people will make mistakes, so the environment needs to be ready for them.
Phishing is also one of the common starting points for a much larger incident. Our guide to ransomware protection for Michigan businesses explains what can happen after the first account or device is compromised, and which layers matter most when the goal is keeping the business running.
Frequently Asked Questions
Can a phishing email come from someone I know?
Yes. If the person's email account has been compromised, the attacker can send messages from the real address and may use existing contacts or conversations to make the request more believable.
Can Microsoft 365 MFA still be tricked?
MFA is still an important protection, but an attacker may try to trick a person into approving a sign-in or entering a device code for a session the attacker started. Stronger sign-in controls, monitoring, and phishing-resistant authentication methods can reduce that risk.
What is device code phishing?
Device code phishing abuses a legitimate sign-in method built for devices that are difficult to log into directly. The attacker starts the process, gives the victim a code, and tries to convince the victim to complete the Microsoft login so the attacker's device or application receives access.
What should a business do after an employee enters credentials or a code?
Contact the IT or security team immediately. The account should be contained, active sessions and tokens revoked, the password reset, sign-ins reviewed, MFA methods checked, mailbox rules inspected, and anyone who received a suspicious message warned.
What I Hope Businesses Take From This
- A familiar sender does not guarantee that the person sent the message.
- A real Microsoft page can still be connected to a bad request.
- Employee awareness matters, but it needs technical protection behind it.
- Fast reporting is more useful than blaming the person who clicked.
- The right layers can turn a serious incident into a blocked link and a phone call.
Related From Simply Technology
Not Sure What Would Stop This in Your Business?
We can review your email security, Microsoft 365 sign-in controls, monitoring, and response process, then give you a clear picture of what is working and what needs attention.
Request a Security Review