HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Device‑Code Phishing Up 1,500% in 2026; Vishing Doubles

Dark Reading reports a 1,500% increase in device‑code phishing and a doubling of vishing attacks in 2026, highlighting a new social‑engineering vector that sidesteps MFA. For SOC 2‑compliant organizations, this underscores the need for robust access‑control monitoring and targeted security awareness training.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
darkreading.com

Device‑Code Phishing Surges 1,500% in 2026; Vishing Activity Doubles

What Happened — Dark Reading reports that “device‑code” phishing attacks—where attackers trick users into authorizing malicious applications via OAuth device‑code flows—have risen 1,500% year‑to‑date, while voice‑phishing (vishing) attempts have doubled over the same period. The techniques sidestep traditional MFA controls and leave minimal forensic artifacts.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6 (Logical Access) expects documented controls that prevent credential compromise through social engineering; the surge shows those controls are being bypassed.
  • Continuous‑monitoring evidence (e.g., MFA logs, anomalous device‑code usage) is now essential to demonstrate “reasonable assurance” during audits.
  • Security Awareness Training (SAT) is a core CC5 (Security) control; the trend underscores the need for regular, scenario‑based training and testing.

Who Is Affected – SaaS providers, enterprise IT departments, and any organization that relies on OAuth/OIDC device‑code authentication (largely TECH_SAAS and FIN_SERV).

Recommended Actions – Review and tighten device‑code flow configurations; enforce MFA on all OAuth authorizations; expand SAT programs to include device‑code and vishing simulations; collect and retain logs that can serve as audit evidence of anomalous authentication attempts. Source: Dark Reading

Technical Notes – Attack vector: phishing (device‑code and voice). No specific CVE; exploits user trust in legitimate device‑code prompts. Data at risk includes privileged tokens and downstream corporate resources. Source: same as above

📰 Original Source
https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →