logo

Device code phishing: it's phishing with dynamite

ID: 16124d5d-dcfc-5831-bb18-e46d2a471c20

STIX ID: report--16124d5d-dcfc-5831-bb18-e46d2a471c20

Feed Name: Okta Threat Intelligence

Threat Score
72/100

Date Published: 2026-05-10

Date Updated: 2026-08-05

Author: Brett Winterford

...
...

Device code phishing — where attackers abuse the OAuth device code grant to induce users to authorize malicious clients — is rapidly increasing and being industrialized. Researchers report a ~15x rise in attacks targeting Microsoft 365 and note threat actors pivoting to this technique, enabled at scale by services like EvilTokens which lower the skill barrier and automate lures and evasion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.