Identity · 55 days ago
Device-code phishing now breaks a control most teams treat as enough: the user can satisfy strong MFA and still hand an attacker access by approving a legitimate device login. The failure is in the authorization step, not the password check, so passkeys and hardware keys do not stop the token theft once the user grants access.
The campaign has moved from niche technique to commodity crime. Push Security tracks more than 25 kits, Barracuda counted 7 million attacks in four weeks, and Microsoft said it was seeing 10 to 15 new campaigns every day in April 2026. ShinyHunters used it against Salesforce tenants, then EvilTokens and Kali365 helped turn it into phishing-as-a-service.
For identity and SaaS teams, the important change is persistence of bearer access after the approval, not just the lure. If users sign into Microsoft 365 or Salesforce with device-code flow, the attacker can ride the real authorization screen and keep using the account and connected apps.
3 sources covering this story
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Push tracks 25-plus device code phishing kits that bypass passkeys; Barracuda counted 7 million attacks in four weeks.
Device Code Phishing Keeps Evolving. Here’s What to Watch For | Huntress
Huntress is tracking an evolving wave of device code phishing that abuses trusted Microsoft 365 sign-in flows.
Part of the PlainSec briefing for 2026-08-05