[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSqlDcI56gDN_A4aG04tv9smUaHLw_UKVBZ0WDB5eMPc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"a1928f3a-acb7-4bc9-a5af-dc7d3421c90b","device-code-phishing-surges-1500-as-social-engineering-evolves-beyond-traditional-defenses","f669c3b3-87ad-4b0d-80dd-d5215b52a54a","Device Code Phishing Surges 1,500% as Social Engineering Evolves Beyond Traditional Defenses","Attackers are exploiting device code authentication flows and voice-based phishing (vishing) to trick users into surrendering credentials or granting unauthorized access, bypassing conventional email-based security filters. These techniques are particularly dangerous because they abuse legitimate authentication protocols (such as OAuth device code flows) and human trust, leaving minimal forensic artifacts for defenders to analyze. The 1,500% surge signals that threat actors are rapidly shifting to methods that exploit user behavior rather than technical vulnerabilities, rendering perimeter defenses alone insufficient. Organizations that rely solely on technical controls without investing in user education and adaptive authentication are especially exposed. This trend underscores that security awareness training and strong identity controls must evolve in lockstep with attacker innovation.","**Immediate actions:**\n- Disable or restrict OAuth device code flow authentication for users and applications that do not explicitly require it.\n- Deploy phishing-resistant MFA methods (e.g., FIDO2\u002Fpasskeys) to replace SMS or app-push-based authentication that vishing can bypass.\n\n**Long-term improvements:**\n- Conduct regular, scenario-based security awareness training that includes device code phishing and vishing simulations.\n- Implement Conditional Access policies that flag or block authentication requests originating from unusual device types, locations, or flows.\n- Establish a Zero Trust identity architecture that continuously verifies user and device posture rather than granting implicit trust.\n\n**Detection measures:**\n- Monitor identity provider logs for anomalous device code authentication attempts, especially from unfamiliar IP ranges or devices.\n- Deploy voice call analytics or telephony security controls to flag spoofed caller IDs and social engineering indicators.\n- Create alerts for bulk or rapid OAuth token issuances that may indicate a successful device code phishing campaign.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","CIS Control 17 – Incident Response Management","NIST SP 800-63B – Digital Identity Guidelines (Phishing-Resistant AAL3)","NIST AC-2 – Account Management","NIST AC-17 – Remote Access","NIST IA-5 – Authenticator Management","NIST AT-2 – Literacy Training and Awareness","MITRE ATT&CK T1528 – Steal Application Access Token","MITRE ATT&CK T1566 – Phishing","GDPR Article 32 – Security of Processing","NIST CSF PR.AT-1 – Awareness and Training","published","2026-08-04T08:20:37.635774+00:00","2026-08-04T08:20:37.482+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.darkreading.com\u002Fcybersecurity-analytics\u002Fdevice-code-phishing-vishing-doubles","device-code-phishing-up-1-500-in-2026-vishing-doubles-f9d8af","Device Code Phishing Up 1,500% in 2026; Vishing Doubles",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]