HackMyIP
← Back to News
2026-08-04 Dark Reading

Device Code Phishing Surges 1,500% as Vishing Attacks Double in 2026

PhishingAuthenticationThreat Intel

Attackers are rapidly abandoning traditional credential-stealing campaigns in favor of social engineering techniques that sidestep multi-factor authentication and leave minimal forensic evidence. According to new threat intelligence highlighted by Dark Reading, Device Code phishing incidents have skyrocketed 1,500% in 2026, while voice-based vishing attacks have doubled year-over-year, signaling a structural shift in how adversaries compromise enterprise identities.

Device Code phishing exploits the OAuth 2.0 Device Authorization Grant, a protocol designed for input-constrained devices such as smart TVs and IoT hardware. Attackers trick victims into visiting a legitimate Microsoft, Google, or third-party identity provider endpoint and entering a short alphanumeric code displayed by an attacker-controlled session. Once submitted, the victim's account issues a token to the attacker's device, effectively bypassing password requirements, hardware security keys, and standard MFA prompts. Because the authentication flow originates from a genuine provider URL, network-level defenses rarely flag the activity, and the only artifacts left behind are a legitimate token issuance and a familiar login record.

Vishing, the second-fastest-growing vector, complements these token-based attacks by targeting help-desk personnel and executives through live phone calls. Operators posing as internal IT staff manipulate agents into resetting MFA enrollments, registering attacker-controlled FIDO2 keys, or approving push notifications in real time. The conversational nature of these campaigns resists the signature-based detection used by email filtering and secure web gateways, and because no malicious payload is ever delivered, endpoint protection platforms register nothing to block.

Defenders are advised to harden the human and procedural layers that these attacks target. Organizations should enforce strict device-binding policies, disable Device Code flows where business needs allow, and require voice callback verification through known numbers before any MFA reset. Individual users can reduce exposure by reviewing their accounts for unfamiliar sessions using a password and credential checker, confirming their browsers do not leak identifying data through a browser fingerprint test, and running a full privacy checkup to identify dormant OAuth grants and stale application permissions that attacker-initiated flows may have left behind.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →