Phishing campaigns continue to evolve. As organizations strengthen credential-based defenses with MFA, password managers, and phishing-resistant authentication, attackers have shifted their focus from stealing credentials to stealing OAuth tokens. One of the most consequential examples of this shift is device code phishing, an attack pattern that abuses a legitimate OAuth 2.0 authentication flow to obtain valid access and refresh tokens without needing the victim’s password and without triggering the protections that defeat traditional phishing.
Device Code Phishing Explained: How Attackers Abuse OAuth Across SaaS
calendar_today
June 9, 2026
person
Martin Vigo, Lead Offensive Security Engineer, AppOmni
domain
appomni