Device‑Code Phishing Surges 1,500% in 2026; Vishing Activity Doubles
What Happened — Dark Reading reports that “device‑code” phishing attacks—where attackers trick users into authorizing malicious applications via OAuth device‑code flows—have risen 1,500% year‑to‑date, while voice‑phishing (vishing) attempts have doubled over the same period. The techniques sidestep traditional MFA controls and leave minimal forensic artifacts.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6 (Logical Access) expects documented controls that prevent credential compromise through social engineering; the surge shows those controls are being bypassed.
- Continuous‑monitoring evidence (e.g., MFA logs, anomalous device‑code usage) is now essential to demonstrate “reasonable assurance” during audits.
- Security Awareness Training (SAT) is a core CC5 (Security) control; the trend underscores the need for regular, scenario‑based training and testing.
Who Is Affected – SaaS providers, enterprise IT departments, and any organization that relies on OAuth/OIDC device‑code authentication (largely TECH_SAAS and FIN_SERV).
Recommended Actions – Review and tighten device‑code flow configurations; enforce MFA on all OAuth authorizations; expand SAT programs to include device‑code and vishing simulations; collect and retain logs that can serve as audit evidence of anomalous authentication attempts. Source: Dark Reading
Technical Notes – Attack vector: phishing (device‑code and voice). No specific CVE; exploits user trust in legitimate device‑code prompts. Data at risk includes privileged tokens and downstream corporate resources. Source: same as above