Device code phishing, a technique that abuses the OAuth 2.0 device authorization grant to steal access tokens, has transitioned from a niche red-team method to an industrial-scale threat within six months. This attack vector, initially described in 2020, saw nation-state actors like Storm-2372 begin using it in 2024, followed by ShinyHunters targeting Salesforce tenants in 2025. The introduction of the EvilTokens kit in February 2026 led to a significant increase in criminal adoption.
By April 2026, Microsoft reported 10 to 15 new campaigns daily, and Barracuda recorded 7 million attacks in four weeks. The FBI issued a standalone advisory on Kali365, marking the first US federal agency public service announcement about a specific phishing-as-a-service kit. Push Security, which added device code phishing to its Browser & Identity Attacks Matrix in 2023, now tracks over 25 distinct device code phishing kits in the wild, indicating a sustained and growing threat.
A critical aspect of device code phishing is its ability to defeat all forms of multi-factor authentication (MFA), including passkeys and hardware security keys. The attack does not target the login flow but rather the authorization layer, occurring after a user has already signed into their account. Victims copy a short code, enter it on a legitimate Microsoft device login page, select their account, and click 'allow', granting access to the attacker. This exploits the distinction between proving identity and granting application access, with most security controls only protecting the former.
The phishing-as-a-service (PhaaS) ecosystem has fully industrialized device code phishing, making it a standard feature in their offerings. This has removed the need for specialized knowledge, allowing a broader range of attackers to deploy this sophisticated technique. The widespread availability of these kits contributes to the rapid increase in attacks and the challenge for security teams to defend against them.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly industrialized into a major threat. This method bypasses all forms of multi-factor authentication, including passkeys, by targeting the authorization layer rather than the login process itself.