At a glance: Device-code phishing has evolved from an isolated attack technique to a widespread threat to enterprise authentication within six months.
Device-code phishing abuses the OAuth 2.0 device grant flow to steal access tokens. The attack form has evolved within six months from a red team technique to a widespread threat.
Device-code phishing targets the OAuth 2.0 device grant flow, which was originally designed for input-constrained devices such as smart TVs and printers. The procedure allows users to log in on devices with limited input capability via a browser on another device – the user receives a device code, enters it on a website and authenticates there.
Attackers abuse this mechanism by sending fraudulent device code prompts. Users are tricked into entering legitimate-looking codes on the authentication page without realizing that these belong to an attacker. This allows attackers to obtain access tokens to enterprise applications and the victim’s accounts – without ever stealing a password.
The threat is growing rapidly because the OAuth device flow is increasingly being used by applications and services that access enterprise resources via web browsers or command-line tools. CISOs must implement detection mechanisms for suspicious device code activities, consistently enforce multi-factor authentication, and train users on this attack method.
Source: thehackernews.com · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.