Device Code Phishing Exploits OAuth 2.0 to Steal Access Tokens at Scale
Device code phishing abuses the legitimate OAuth 2.0 device authorization grant flow, tricking users into authorizing attacker-controlled devices by presenting convincing login prompts — bypassing traditional credential-based defenses entirely. Because the attack yields long-lived access tokens rather than passwords, MFA provides little protection and stolen sessions can persist undetected for extended periods. Nation-state actors and criminal groups have industrialized this technique, making it one of the fastest-growing identity-based threats. Organizations that lack visibility into OAuth token issuance and device authorization events are essentially blind to this class of attack. The human element remains central — users who don't recognize the device code flow as a potential attack vector are the primary enabler.
Tactical Insight
Immediate actions
- Restrict or disable the OAuth 2.0 device authorization grant flow for users and applications that do not require it via Conditional Access or identity provider policies.
- Enforce strict token lifetime limits and enable continuous access evaluation (CAE) to revoke stolen tokens in near real-time.
Detection measures
- Enable logging of all OAuth token issuance events and alert on device code grant flows originating from unfamiliar devices, locations, or outside business hours.
- Integrate identity provider audit logs into your SIEM and create detections for anomalous token usage patterns, such as tokens used from multiple geolocations.
Long-term improvements
- Conduct regular security awareness training that specifically covers OAuth phishing scenarios, including how device code prompts look and why users should never authorize unknown devices.
- Implement phishing-resistant MFA (e.g., FIDO2/passkeys) and adopt a Zero Trust posture that continuously validates device health and user context before granting resource access.
- Maintain an up-to-date application inventory and periodically review OAuth app permissions to remove unnecessary or overprivileged integrations.