← Back to Feed

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

July 31, 2026 · The Hacker News · Severity: LOW

Device code phishing, which exploits the OAuth 2.0 device authorization grant to steal access tokens, has rapidly become a major threat in 2026. Originally used in red-team exercises, it now operates at scale, targeting devices like smart TVs and printers with constrained input capabilities.

Key Takeaways

  • Device code phishing abuses OAuth 2.0 device authorization grant.
  • This threat has evolved into an industrial-scale attack in six months.
  • It targets input-constrained devices like smart TVs and printers.
☕ Buy a Coffee