As cited
Copy frozen at (site build).
threat intel
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Greatness, a commercial phishing-as-a-service toolkit, has added device code phishing capabilities that exploit OAuth 2.0 Device Authorization Grant flows to circumvent MFA protections and compromise user accounts. This technique allows attackers to intercept legitimate authentication mechanisms and gain account control without triggering traditional security alerts.
Why it matters: Organizations relying on MFA as their primary defense against account takeover must recognize that device code phishing defeats standard MFA protections; security teams should implement conditional access policies, monitor for unusual device authorizations, and educate users on device code phishing risks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Greatness, a commercial phishing-as-a-service (PhaaS) toolkit, has added device code phishing capabilities to its offering. This technique exploits the OAuth 2.0 Device Authorization Grant flow to circumvent multifactor authentication (MFA) and compromise user accounts.
Why it matters: Organizations using OAuth 2.0 and MFA face elevated account takeover risk as attackers leverage mainstream phishing tools with MFA-bypassing techniques, making credential defense and device code monitoring critical.
- Source published
- First seen by Cybersecurity Tracker