RL recently discovered active Microsoft 365 device code phishing. Here's a walkthrough of how our researchers found the campaign.