Cyber Resilience
← All news
Corroborated

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Our takeI don't doubt the 1,500 percent growth these reports document, but absolute volumes would help frame how big a problem it actually is. Disable the OAuth device authorization grant anywhere it is not required.
Sources (2)
What this means for you — Security leader:Device code phishing has grown rapidly in 2026; review OAuth device authorization grant usage in your apps, enforce strict redirect URIs and token binding where possible, and monitor for anomalous token requests from non-browser clients.
What this means for you — Lean IT orgs:Device code phishing attacks rose sharply this year by abusing login flows meant for TVs and printers; if any of your cloud apps or tools use this login method, turn it off where you can and watch for unexpected login emails.
What this means for you — MSP:Device code phishing is up 1,500% in 2026 and bypasses many standard controls; audit client environments for OAuth device grant usage, disable where unnecessary, and add monitoring for suspicious token issuance across managed tenants.
What this means for you — Researcher:Corroborated reports show device code phishing scaling from red-team technique to industrial threat in months; track adoption curves, measure bypass efficacy against existing MFA and conditional access, and test detection for anomalous device-flow activity.