In a nutshell: In 2026, device code phishing and vishing are specifically designed to bypass established security controls such as MFA and email filters while leaving significantly fewer forensic traces.
Newer social engineering techniques allow attackers to bypass established security controls while leaving significantly fewer forensic traces. For CISOs, this means that classic phishing defenses are increasingly falling short.
Current analyses show a 1,500 percent increase in device code phishing in 2026. In this technique, attackers abuse the OAuth device authorization flow, which is actually intended for devices without a browser or keyboard, such as smart TVs or IoT devices. Users are tricked into entering a legitimate login code on a genuine Microsoft or Google login page, allowing attackers to obtain a valid access token without needing to capture classic credentials such as passwords. At the same time, vishing—phishing via phone call—has doubled over the same period.
Both techniques share the trait of specifically bypassing established technical controls such as multi-factor authentication, email filters, or URL reputation checks. Because device code phishing involves logging in via a legitimate page of the respective identity provider, many classic phishing detection mechanisms that target fake login pages or suspicious URLs fail to catch it. Vishing, in turn, exploits human interaction over the phone, where social engineering elements such as urgency or fake IT support requests are harder to detect automatically than in written communication.
For security leaders, this creates a dual challenge: on the one hand, these types of attacks leave fewer usable forensic traces than classic credential phishing, which complicates incident response and attribution. On the other hand, defense requires a combination of technical measures—such as restricting or monitoring device code flows within one’s own identity infrastructure—and organizational measures, such as targeted awareness training on vishing scenarios and verified callback processes for purported IT support requests.
CISOs should check whether their identity provider configuration actually requires the device code flow and, if not, disable it or restrict it using conditional access policies. It is also advisable to review existing detection use cases in the SIEM or SOC to determine whether unusual device code logins and call patterns related to helpdesk impersonation are being captured at all.
Source: www.darkreading.com · Published August 4, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.