logo

Device-Code Phishing Jumped 1,380%: The MFA Bypass Method Nobody’s Training Employees On

ID: e58a9adc-8b5c-5dd4-aa64-6e25e26cadbb

STIX ID: report--e58a9adc-8b5c-5dd4-aa64-6e25e26cadbb

Feed Name: Brandefense Blog

Threat Score
80/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Onur Can Arslan

...
...

This briefing details the rapid emergence and industrialisation of device code phishing, an OAuth device authorization abuse that sends legitimate provider login prompts to victims so attackers can harvest access and long‑lived refresh tokens; it documents massive growth (1,380% increase), daily new campaigns and phishing kits, explains why the technique defeats phishing‑resistant MFA, and provides detection signals and remediation steps (block or alert on device_code grants, revoke refresh tokens, and change awareness training).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.