How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Device Code Phishing Explained: How Attackers Abuse OAuth Across SaaS

calendar_today June 9, 2026 person Martin Vigo, Lead Offensive Security Engineer, AppOmni domain appomni

Phishing campaigns continue to evolve. As organizations strengthen credential-based defenses with MFA, password managers, and phishing-resistant authentication, attackers have shifted their focus from stealing credentials to stealing OAuth tokens. One of the most consequential examples of this shift is device code phishing, an attack pattern that abuses a legitimate OAuth 2.0 authentication flow to obtain valid access and refresh tokens without needing the victim’s password and without triggering the protections that defeat traditional phishing.

open_in_new Read original post