General session image of Knowledge Forum E

Underestimated and Dangerous: How BEC Attacks Circumvent Modern Authentication

When MFA becomes an illusion: device code flow phishing – a legitimate sign-in mechanism as an entry point. Attack, detection, defence.

Topic

Awareness / Phishing / FraudCloud SecuritySIEM / Threat Analytics / SOCManaged Security Services / Hosting

When & Where

calendar_month

Thu, 10/29/2026 11:00 AM - 11:15 AM

location_on

Forum E, Booth 9-105

Download session as iCaldownload_for_offline

Details

  • Format:

    Technology lecture

  • Language:

    German

Session description

Speaker: Christian Kollee Business 

Email Compromise (BEC) is one of the most underestimated cyber threats of our time - and simultaneously the most common incident type handled by Eye Security's SOC: over 190 cases this year alone. This talk examines an attack technique that is increasingly gaining traction among cybercriminals: Device-Code-Flow Phishing. This method abuses a legitimate authentication mechanism to bypass multi-factor authentication, giving attackers undetected access to email and sensitive corporate data. We will demonstrate how these attacks work in technical terms, why they are so difficult to detect, and what concrete measures organisations can take to effectively protect their employees.

Sponsored by