Our takeI don't doubt the 1,500 percent growth these reports document, but absolute volumes would help frame how big a problem it actually is. Disable the OAuth device authorization grant anywhere it is not required.Cyber Resilience desk
Sources (2)
- hackernews · hackernews
- darkreading · darkreading
What this means for you — Security leader:Device code phishing has grown rapidly in 2026; review OAuth device authorization grant usage in your apps, enforce strict redirect URIs and token binding where possible, and monitor for anomalous token requests from non-browser clients.
What this means for you — Lean IT orgs:Device code phishing attacks rose sharply this year by abusing login flows meant for TVs and printers; if any of your cloud apps or tools use this login method, turn it off where you can and watch for unexpected login emails.
What this means for you — MSP:Device code phishing is up 1,500% in 2026 and bypasses many standard controls; audit client environments for OAuth device grant usage, disable where unnecessary, and add monitoring for suspicious token issuance across managed tenants.
What this means for you — Researcher:Corroborated reports show device code phishing scaling from red-team technique to industrial threat in months; track adoption curves, measure bypass efficacy against existing MFA and conditional access, and test detection for anomalous device-flow activity.