CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3828

As cited

Copy frozen at (site build).

threat intel

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness, a commercial phishing-as-a-service toolkit, has added device code phishing capabilities that exploit OAuth 2.0 Device Authorization Grant flows to circumvent MFA protections and compromise user accounts. This technique allows attackers to intercept legitimate authentication mechanisms and gain account control without triggering traditional security alerts.

Why it matters: Organizations relying on MFA as their primary defense against account takeover must recognize that device code phishing defeats standard MFA protections; security teams should implement conditional access policies, monitor for unusual device authorizations, and educate users on device code phishing risks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness, a commercial phishing-as-a-service (PhaaS) toolkit, has added device code phishing capabilities to its offering. This technique exploits the OAuth 2.0 Device Authorization Grant flow to circumvent multifactor authentication (MFA) and compromise user accounts.

Why it matters: Organizations using OAuth 2.0 and MFA face elevated account takeover risk as attackers leverage mainstream phishing tools with MFA-bypassing techniques, making credential defense and device code monitoring critical.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary