CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3775

As cited

Copy frozen at (site build).

threat intel

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Device code phishing attacks surged 1,500% in 2026 while vishing (voice phishing) calls doubled, reflecting a shift toward social engineering methods that bypass traditional security controls. These techniques enable attackers to operate with minimal forensic footprint, making detection and attribution more difficult for defenders.

Why it matters: Security teams need to recognize that MFA and endpoint controls alone are insufficient; social engineering attacks targeting users directly are accelerating and require user awareness training, call authentication, and behavioral detection alongside technical controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Device code phishing attacks surged 1,500 percent in 2026, while voice-based social engineering (vishing) doubled during the same period. Both attack vectors allow adversaries to bypass established security controls and minimize forensic artifacts.

Why it matters: Security teams need to prioritize detection and user training for device code and vishing attacks, as these methods circumvent multi-factor authentication and leave minimal logging evidence that traditional incident response relies on.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary