Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Device Code Phishing Exploits OAuth 2.0 Grant to Hijack User Accounts

Attackers manipulate the OAuth 2.0 Device Authorization Grant to trick users into approving malicious sign‑ins, granting the attacker access tokens without a password. This underscores the need for robust access‑control monitoring and evidence collection for audit readiness.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

Device Code Phishing Exploits OAuth 2.0 Grant to Hijack User Accounts

What Happened — Attackers are abusing the OAuth 2.0 Device Authorization Grant, a legitimate sign‑in flow for “headless” devices, to trick users into entering a short code on a genuine Microsoft (or other IdP) sign‑in page. Once the victim approves the request, the attacker receives authentication tokens that grant access to the victim’s account, often bypassing password‑only controls and even MFA.

Why It Matters for Trust & Control Assurance

  • Demonstrates how a standard authentication flow can become a vector for credential compromise when user‑initiated approvals are not tightly governed.
  • Highlights the need for continuous monitoring of token issuance and anomalous device‑code activity as evidence of effective access‑control assurance.
  • Aligns with the Identity & Access Management control objective: enforce least‑privilege, verify authentication requests, and maintain auditable logs of token grants.

Who Is Affected

  • Enterprise SaaS platforms that rely on OAuth 2.0 (e.g., Microsoft 365, Azure AD, Google Workspace).
  • Organizations with large user bases using cloud‑based collaboration tools.

Recommended Actions

  • Enforce conditional‑access policies that block or require additional verification for device‑code flows from untrusted apps.
  • Deploy security‑awareness training focused on recognizing unsolicited code‑entry requests.
  • Implement continuous monitoring of OAuth token issuance and generate alerts on abnormal device‑code activity.
  • Review MFA configurations to ensure users cannot inadvertently approve malicious sign‑ins.

Technical Notes

  • Attack leverages the OAuth 2.0 Device Authorization Grant (RFC 8628).
  • No specific CVE; the technique exploits a design feature rather than a software flaw.
  • Tokens issued can grant access to email, files, contacts, and other services depending on granted scopes.

Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/how-to/2026/09/how-device-code-phishing-gives-scammers-access-to-your-account ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →