Device-Code Phishing Goes Industrial and Bypasses Passkeys
Device-code phishing now breaks a control most teams treat as enough: the user can satisfy strong MFA and still hand an attacker access by approving a legitimate device login. The failure is in the authorization step, not the password check, so passkeys and hardware keys do not stop the token theft once the user grants access.
The campaign has moved from niche technique to commodity crime. Push Security tracks more than 25 kits, Barracuda counted 7 million attacks in four weeks, and Microsoft said it was seeing 10 to 15 new campaigns every day in April 2026. ShinyHunters used it against Salesforce tenants, then EvilTokens and Kali365 helped turn it into phishing-as-a-service.
For identity and SaaS teams, the important change is persistence of bearer access after the approval, not just the lure. If users sign into Microsoft 365 or Salesforce with device-code flow, the attacker can ride the real authorization screen and keep using the account and connected apps.