logo

Device code phishing: it's phishing with dynamite

ID: d4aa2570-4134-5cce-915a-d7a75f4e8d22

STIX ID: report--d4aa2570-4134-5cce-915a-d7a75f4e8d22

Feed Name: Okta Threat Intelligence

Threat Score
75/100

Date Published: 2026-05-10

Date Updated: 2026-08-05

Author: Brett Winterford

...
...

Device code phishing — abuse of the OAuth device-code authentication flow to trick users into authorizing attacker-controlled apps — is surging. Researchers report a 15x increase targeting Microsoft 365 users and note that phishing-as-a-service platforms like EvilTokens have industrialized the attack, allowing low-skilled actors to scale account-takeover operations; the article explains the flow, how it is exploited, and why the technique is particularly dangerous.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.