As cited
Copy frozen at (site build).
threat intel
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly escalated from a specialized red-team technique to an industrial-scale threat within six months. The attack method targets the device authorization login flow, originally designed for input-constrained devices like smart TVs and printers, but now adopted across a wider range of applications and use cases.
Why it matters: Security practitioners should monitor this growing attack vector as organizations increasingly implement device authorization flows in applications beyond their original scope, expanding the potential attack surface for token theft and unauthorized access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing exploits the OAuth 2.0 device authorization grant to steal access tokens and has escalated from a specialized red-team technique to widespread attacks in less than six months. Originally designed for input-constrained devices like smart TVs and printers, the authorization flow has been adopted across many applications beyond its intended scope.
Why it matters: Organizations and users relying on device-based authentication flows are exposed to token theft; practitioners should review which applications use device code flows and implement phishing-resistant controls.
- Source published
- First seen by Cybersecurity Tracker