6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 — [https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiamJN4Z-p-XmpB_1nwgfCMj
What’s new: Device code phishing, leveraging the OAuth 2.0 device authorization grant, has rapidly evolved into a significant threat, with reports of 10 to 15 new campaigns daily as of April 2026. This technique bypasses all forms of multi-factor authentication (MFA) by targeting the authorization layer after users have already logged in. The FBI has issued advisories on phishing-as-a-service kits like Kali365, which facilitate these attacks. Over 25 distinct device code phishing kits are now tracked, with attacks primarily targeting Microsoft accounts but expanding to other platforms.
Who’s affected
While 99% of current device code phishing attacks target Microsoft accounts, any application implementing the OAuth 2.0 device authorization grant is at risk. This includes platforms like GitHub and AWS, which are increasingly being targeted as attackers expand their toolkit.
What to do
- Implement conditional access policies to restrict device code authentication flows where feasible.
- Enhance monitoring and detection capabilities specifically for device code phishing techniques, focusing on behavioral signatures rather than specific kit fingerprints.
- Educate users about the risks of device code phishing and encourage vigilance when entering codes on legitimate login pages.
- Consider deploying browser-layer security tools that can detect and mitigate advanced phishing attacks in real-time.



