Device Code Phishing: The Fastest-Growing Cyber Threat of 2026

Device code phishing, a method exploiting the OAuth 2.0 device authorization grant to steal access tokens, has rapidly escalated from a niche technique to a widespread cyber threat within a few months in 2026. Originally designed for devices with limited input capabilities, such as smart TVs and printers, this authentication flow has been increasingly misused across various applications, notably command-line interface (CLI) logins.

While researchers identified this vulnerability in 2020, it wasn’t until 2024 that nation-state actors like Storm-2372 began leveraging it. By 2025, groups such as ShinyHunters were targeting Salesforce tenants using device code phishing. The trend intensified in February 2026 with the emergence of the EvilTokens kit, leading to a significant surge in criminal activities. By April, Microsoft reported 10 to 15 new campaigns daily, and Barracuda recorded seven million attacks over four weeks. The FBI responded by issuing a dedicated advisory on the Kali365 phishing-as-a-service (PhaaS) kit, marking the first federal alert focused on a specific phishing tool.

1. Bypassing Multi-Factor Authentication (MFA)

Device code phishing attacks the authorization layer post-login, rendering traditional MFA methods, including passkeys and hardware security keys, ineffective. Victims, often already signed into their Microsoft accounts, are tricked into entering a short code on the legitimate Microsoft device login page, thereby granting attackers access without compromising the initial authentication process.

2. Industrialization of Phishing-as-a-Service

The PhaaS ecosystem has rapidly integrated device code phishing into its offerings. Kits like Tycoon2FA and Kali365 now provide both adversary-in-the-middle (AiTM) and device code phishing capabilities. Advanced tools such as ARToken offer features like Primary Refresh Token (PRT) persistence, mailbox access, business email compromise (BEC) automation, and SharePoint exfiltration, making sophisticated attacks accessible to a broader range of cybercriminals.

The swift evolution of device code phishing underscores the adaptability of cybercriminals and the challenges in securing authentication processes. Organizations must stay vigilant, continuously update their security protocols, and educate users about emerging threats to mitigate the risks associated with this rapidly growing attack vector.