Device-Code Phishing Jumped 1,380%: The MFA Bypass Method Nobody’s Training Employees On
ID: e58a9adc-8b5c-5dd4-aa64-6e25e26cadbb
STIX ID: report--e58a9adc-8b5c-5dd4-aa64-6e25e26cadbb
Feed Name: Brandefense Blog
This briefing details the rapid emergence and industrialisation of device code phishing, an OAuth device authorization abuse that sends legitimate provider login prompts to victims so attackers can harvest access and long‑lived refresh tokens; it documents massive growth (1,380% increase), daily new campaigns and phishing kits, explains why the technique defeats phishing‑resistant MFA, and provides detection signals and remediation steps (block or alert on device_code grants, revoke refresh tokens, and change awareness training).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
