Device code phishing rises sharply by abusing OAuth 2.0 device grants
Source headline: 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Intelligence Summary
Device code phishing is rapidly expanding by abusing the OAuth 2.0 device authorization grant to steal access tokens. The technique targets login flows used by input-constrained devices such as smart TVs, printers, and similar endpoints. Attackers leverage the device-code flow to make authentication prompts feel legitimate while compromising user sessions. Because many apps and services adopted this OAuth flow for convenience, the risk spreads across a wide range of ecosystems. Users should watch for unexpected login confirmations and ensure strong account protections like MFA where supported. Organizations should review OAuth configuration and reduce exposure to token theft via device-code phishing patterns.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.