04/13/2026
WARNING: Hackers Are Stealing Microsoft Accounts — Even If You Use 2FA!
A major new scam is hitting hundreds of thousands of people across the US, Canada, Australia, and more. Hackers are sending fake emails that trick you into handing over your Microsoft 365 account — and the scariest part? Changing your password won't fix it.
Here's how it works in plain English
1. You get a suspicious email
It looks legit — maybe about a document, a voicemail, a DocuSign request, or a construction bid. It has a button or link to click.
2. You're shown a code and sent to Microsoft's real website
The page looks completely real because it IS Microsoft's real login page. You're asked to type in a short code to "verify" yourself.
3. You log in with your username, password, AND your 2FA code
This feels safe because you're on Microsoft's actual page. But the code you typed was secretly generated by the hacker.
4. The hacker now owns your account — permanently
They get a special "key" that lets them into your account forever. Even if you change your password, their key still works.
What NOT to do
✕ Don't click links in unexpected emails — even if they look like they're from Microsoft, DocuSign, or your boss.
✕ Don't type a code into microsoft.com/devicelogin unless YOU started the process (like setting up a new TV or device).
✕ Don't assume 2FA protects you here — this scam bypasses it completely.
✕ Don't trust an email just because the link looks real — hackers disguise dangerous links behind trusted names like Cisco and Mimecast.
✕ Don't think only big companies are targeted — nonprofits, healthcare workers, real estate agents, and government employees are all being hit.
What to do instead
✓ If you think you were tricked, contact your IT department immediately — they need to revoke your access tokens, not just reset your password.
✓ When in doubt about an email, call the sender directly using a number you already know — not one in the email.
✓ Share this post with coworkers, friends, and family — especially anyone who uses Microsoft 365 for work.
HUGE red flag is getting a request to sign into microsoft.com/devicelogin if you didn't request it