← All stories
● Covered by 1 source · 1 reportHigh impact1 negative

Device Code Phishing Emerges as a Rapidly Growing Threat, Bypassing MFA

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Device code phishing exploits OAuth 2.0 device authorization grant.
  • It bypasses all MFA, including passkeys, by targeting authorization.
  • Nation-state actors and criminal groups are using this technique at scale.
  • Phishing-as-a-service kits have industrialized device code phishing.

Rise of Device Code Phishing

Device code phishing, a technique that abuses the OAuth 2.0 device authorization grant to steal access tokens, has transitioned from a niche red-team method to an industrial-scale threat within six months. This attack vector, initially described in 2020, saw nation-state actors like Storm-2372 begin using it in 2024, followed by ShinyHunters targeting Salesforce tenants in 2025. The introduction of the EvilTokens kit in February 2026 led to a significant increase in criminal adoption.

Escalating Threat Landscape

By April 2026, Microsoft reported 10 to 15 new campaigns daily, and Barracuda recorded 7 million attacks in four weeks. The FBI issued a standalone advisory on Kali365, marking the first US federal agency public service announcement about a specific phishing-as-a-service kit. Push Security, which added device code phishing to its Browser & Identity Attacks Matrix in 2023, now tracks over 25 distinct device code phishing kits in the wild, indicating a sustained and growing threat.

MFA Bypass Mechanism

A critical aspect of device code phishing is its ability to defeat all forms of multi-factor authentication (MFA), including passkeys and hardware security keys. The attack does not target the login flow but rather the authorization layer, occurring after a user has already signed into their account. Victims copy a short code, enter it on a legitimate Microsoft device login page, select their account, and click 'allow', granting access to the attacker. This exploits the distinction between proving identity and granting application access, with most security controls only protecting the former.

Industrialization by PhaaS Ecosystem

The phishing-as-a-service (PhaaS) ecosystem has fully industrialized device code phishing, making it a standard feature in their offerings. This has removed the need for specialized knowledge, allowing a broader range of attackers to deploy this sophisticated technique. The widespread availability of these kits contributes to the rapid increase in attacks and the challenge for security teams to defend against them.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly industrialized into a major threat. This method bypasses all forms of multi-factor authentication, including passkeys, by targeting the authorization layer rather than the login process itself.