OFICIAL CERN News

Computer Security: One click to many

What happened
Based on CERN News · Jul 28, 2026

CERN reports a phishing campaign bypassing two-factor authentication via Microsoft’s device code feature, compromising over 5,000 accounts and prompting urgent security reviews and user vigilance.

Video

Video available

Key points
·
With the roll-out of two-factor authentication, such campaigns the company is dropped.
·
However, the world continues to turn and novel functionality and novel attack vectors try to circumvent its protections.
·
Arriving in the mailbox of an unlucky colleague, an innocent-looking email was met with the usual response.
·
Basically, this is a locally installed token, valid for 90 days, that makes your life easier by not requiring you to log into Microsoft cloud services on a daily basis.
Key numbers
·
A recent phishing attack at CERN bypassed two-factor authentication by exploiting Microsoft’s device code authentication, which grants 90-day access without daily logins.
·
The attack relied on a Microsoft cloud configuration that bypasses CERN’s two-factor authentication by using locally installed tokens valid for 90 days.

A recent phishing attack at CERN bypassed two-factor authentication by exploiting Microsoft’s device code authentication, which grants 90-day access without daily logins. The attack began with an email containing a link to a Word document hosted on an external domain, masquerading as a legitimate request for a verification code. Victims who entered the code on the subsequent page unknowingly handed full account access to attackers, who then used AI to identify and target additional recipients within the organization.

The compromise spread to more than 5,000 CERN email addresses, with 108 recipients clicking the malicious link. Microsoft revoked the compromised tokens for these accounts, requiring users to re-authenticate via CERN’s two-factor protected Single Sign-On. While the Computer Security Office explores further mitigations, such as disabling device code authentication or reducing token validity, the incident underscores the evolving tactics of attackers.

The attack relied on a Microsoft cloud configuration that bypasses CERN’s two-factor authentication by using locally installed tokens valid for 90 days. This feature, designed to simplify logins, inadvertently provided attackers with persistent access once the initial verification code was entered. The compromised accounts were then used to launch further phishing attempts, creating a cascading effect across the organization.

CERN urges staff to exercise caution, emphasizing the importance of verifying links before clicking. Users are advised to hover over URLs to check their destinations and avoid entering verification codes from unexpected sources. The organization also directs users to its Monthly Report for security updates and provides contact details for further assistance at Computer.Security@cern.ch.

Original source → Deals on Clipraptor.com →