Device Code Phishing
phishing

Device Code Phishing: Why Even Passkeys Won't Save Your Microsoft Tenant

A phishing wave against Microsoft 365 bypasses MFA and even phishing-resistant passkeys without faking a single pixel of Microsoft. What attackers do, why it works, and the conditional access policy that stops it.

April 26, 2026 · 5 min · David Leeuwestein
A smartphone receiving an SMS
phishing

Eleven Characters, No Authentication

An SMS lands in the real Trade Republic chat — and costs a 63-year-old his retirement savings. What makes alphanumeric sender IDs so phishable, and why the UK and Singapore are ahead of Germany.

April 26, 2026 · 7 min · David Leeuwestein
Hello World
meta

Hello World

The first post on lwst.io — what this blog is and who's behind it. No marketing language, no tool reviews — just notes from working in the field and studying.

April 25, 2026 · 1 min · David Leeuwestein