Device Code Phishing Surges: 7 Million Attacks in Four Weeks in 2026
Executive Briefing
- Barracuda recorded 7 million device code phishing attacks within a single four-week period in 2026.
- Push identified 25-plus active phishing kits capable of bypassing passkey authentication protections.
- Device code phishing exploits OAuth device authorization flows, making it harder for users to detect.
- Researchers warn organizations to reassess authentication strategies as traditional MFA proves insufficient.
Sponsored