Utopia Tech
SecurityAI-assisted1 min read

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly escalated from a specialized red-team tactic to a widespread enterprise threat in less than six months. Originally designed for input-limited devices like smart TVs and printers, the device authorization flow has been adopted across numerous applications beyond its intended scope, crea

UT

Utopia Tech

July 31, 2026 · 1 min read

Share

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content