6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing, the abuse of the OAuth 2.0 device authorization grant to steal access tokens, has evolved from a niche red-team technique to an industrial-scale threat in under six months. It defeats every form of MFA, including passkeys, and is now a standard featu…
Intelligence analysis by Llama

Device code phishing is a growing threat that bypasses all MFA, including passkeys, and is now a standard feature in the phishing-as-a-service catalog. It's not just a Microsoft problem, as any application that implements the OAuth 2.0 device authorization grant is a potential target.
Device code phishing is a type of attack that tricks people into giving away secret codes that let attackers access their accounts. It's like a fake login page that looks real, but it's actually a trick to get the code. This type of attack is hard to stop because it looks like a real login page and can bypass all kinds of security measures.
Analysis
A $60B Vote of Confidence
Device code phishing has evolved from a niche red-team technique to an industrial-scale threat in under six months. This rapid growth reflects the maturity of the existing phishing-as-a-service market and the speed at which AI-assisted development lets new capabilities get built and distributed. The technique has been adopted by a wide range of apps and use-cases that it wasn't originally intended for, most commonly CLI logins.
Why Cursor?
Attackers are moving away from the authentication layer because that's where defenders have concentrated their control. Device code phishing is less universally applicable than AiTM - not every app implements the device authorization grant - but it has the advantages of bypassing all MFA, not requiring cloning a login page, and the user interacting with legitimate provider URLs. Apps like GitHub, AWS, and others all support device code flows, and for GitHub it's a core part of how developers authenticate CLI tools and VS Code tunnels.
The Road Ahead
The commercialization pattern mirrors what happened with AiTM phishing: a technique moves from a research curiosity to nation-state espionage to a criminal commodity, each stage accelerating faster than the last. But device code phishing completed that entire journey in a matter of months - a compression that reflects both the maturity of the existing PhaaS market and the speed at which AI-assisted development lets new capabilities get built and distributed. As kit developers look beyond Microsoft, these are the targets that open up.
Key points
- Device code phishing is a growing threat that bypasses all MFA, including passkeys.
- It's not just a Microsoft problem, as any application that implements the OAuth 2.0 device authorization grant is a potential target.
- Attackers are moving away from the authentication layer because that's where defenders have concentrated their control.
- Device code phishing is less universally applicable than AiTM - not every app implements the device authorization grant - but it has the advantages of bypassing all MFA, not requiring cloning a login page, and the user interacting with legitimate provider URLs.
If security teams can stay ahead of the pace of new device code phishing kits emerging, they may be able to mitigate the threat. This could involve developing new security controls that can detect and prevent device code phishing attacks, as well as educating users about the risks of this type of attack.
The rapid growth of device code phishing kits and the ease with which new kits can be built and distributed make it a difficult threat to combat. If security teams are not able to stay ahead of the pace of new kits emerging, the threat of device code phishing may continue to grow.


