Device-code phishing surges 1,500% as vishing attacks double
A new report shows device-code phishing attacks rose by 1,500% over the past year, while voice phishing (vishing) has doubled. Credential theft is moving away from traditional email lures. Device-code phishing abuses the OAuth device authorization flow used by services such as Microsoft 365 and cloud collaboration tools. The victim is tricked into approving a legitimate-looking sign-in code, which hands the attacker a valid session token. That token bypasses passwords and most multi-factor authentication. These campaigns are increasingly paired with vishing: an attacker poses as IT helpdesk staff on the phone and talks the target through the approval step in real time. MFA alone no longer closes this gap, and the attacks focus on finance teams, executive assistants and IT support staff with access to sensitive systems. Restrict or disable device-code authentication where you don't need it. Move to phishing-resistant, hardware-based MFA (FIDO2/passkeys). Require a callback to verify any request that comes from the helpdesk, and give high-value staff targeted vishing-awareness training. Make monitoring for unusual device-authorization requests a priority detection use case.