LOWPhishing
Global
Device code phishing attacks surge 37x as new kits spread online
Saturday, April 4, 2026 at 02:17 PM UTC·Source: BleepingComputer
Updated: Monday, April 6, 2026 at 12:17 AM UTC
Executive Summary
Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. [...]
Analysis
Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. [...]