← Back to Feed
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
July 31, 2026 · The Hacker News · Severity: LOW
Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly become a major threat in 2026. Originally used in red-team exercises, it now operates at scale, targeting devices like smart TVs and printers with constrained input capabilities.
Key Takeaways
- Device code phishing abuses OAuth 2.0 device authorization grant.
- This threat has evolved into an industrial-scale attack in six months.
- It targets input-constrained devices like smart TVs and printers.