CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ✉ Email Security Aug 04, 2026

Device Code Phishing Up 1,500% in 2026; Vishing Doubles - Dark Reading

Dark Reading Archived Aug 04, 2026 ✓ Full text saved

Device Code Phishing Up 1,500% in 2026; Vishing Doubles Dark Reading

Full text archived locally
✦ AI Summary · Claude Sonnet


    CYBERSECURITY ANALYTICS THREAT INTELLIGENCE ENDPOINT SECURITY MOBILE SECURITY NEWS Device Code Phishing Up 1,500% in 2026; Vishing Doubles Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind. Nate Nelson,Contributing Writer August 4, 2026 4 Min Read SOURCE: ABU HANIFAH VIA GETTY IMAGES Phishing is evolving faster than it has in a long, long time. Email-based phishing undisputedly has been the most dominant means of social engineering in the 21st century. It hasn't changed much in that time, and attackers followed pretty much the same basic principles, evolving mostly in their efficacy and ease of operation. In the first half of 2026, though, attackers have been graduating in droves to relatively newer, less obvious phishing techniques. Crowdstrike tracked a doubling of voice phishing (vishing) attacks in this period, according to its newly released 2026 Threat Hunting Report. In the same time period, it tracked a 15-fold increase in device code phishing. Both techniques are helping state-sponsored threat actors and cybercriminal groups bypass traditional security controls. Device Code Phishing Explodes On Oct. 13, 2020, the high-profile Microsoft researcher Nestori Syynimaa published a blog post in which he invented the technique now known as device code phishing. Related:Stronger AI Safety Requires Peeking Inside the 'Black Box' It took a long time for anyone else to catch on. Only in August 2024 did a Russian nation-state threat actor, tracked by Microsoft as "Storm-2372," have the bright idea to try out Syynimaa's technique in a proper cyberattack campaign. By doing so, it managed to compromise organizations across major industries — government, defense, energy, and others — and broad regions — North America, Europe, Africa, and the Middle East — before Microsoft finally discovered and described it in a public blog post the following year. Slowly over the course of 2025, the technique trickled down from the Russian state to cybercriminal groups. Multiple research groups independently noticed a steady rise in device code phishing as 2025 went on, most notably by actors associated with Tycoon 2FA, the world's leading phishing operation at the time. In 2026, device code phishing is becoming mainstream. CrowdStrike observed 15 times more such attacks through the first half of this year than it had through the second half of last. In particular, it noted that attackers are using the technique to compromise cloud identities. "A diverse set" of cybercriminals is doing it now, CrowdStrike wrote, the most prominent among them being the Russian advanced persistent threat (APT) group known as Cozy Bear. CrowdStrike describes other financially motivated device code phishers as followers of Cozy Bear's model, "deploying dedicated device code and session management infrastructure, leveraging legitimate cloud-based hosting services, and delivering device code phishing pages via Entra ID application OAuth redirection at scale." Related:Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs Hackers Choose Vishing for Stealthier Attacks Vishing was already on the rise going into 2025, and lately its momentum has been accelerating. CrowdStrike measured a 134% increase in vishing from 2024 to 2025. From H2 2025 to H1 2026, vishing rates doubled. Two of the biggest threat actors utilizing vishing today are tracked by CrowdStrike as "Cordial Spider" and "Snarky Spider." Each uses the technique to ultimately gain access to victims' single sign-on (SSO)-integrated software-as-a-service (SaaS) applications — valuable sources of corporate secrets. They do it by first directing victims to SSO-themed adversary-in-the-middle (AiTM) pages on their mobile devices. The attackers tailor the phishing pages to the victims they're interested in, and attacking them on their mobile devices often means avoiding the security software victims often install only on their laptop and desktop computers. Once victims hand over their credentials and multifactor authentication (MFA) codes, the threat actors authenticate and then attempt to register their own MFA devices for persistent access to victims' networks. New device registration is a meaningful early-stage signal defenders look for in these attacks, as CrowdStrike observed in a case back in February. In four minutes flat, Cordial Spider had successfully vished a victim, authenticated to their network, and registered a new allowed MFA device. The new device listing raised alarms, though, alerting the victim and empowering them to boot out their attacker only 12 minutes later. Related:Europe Evolves Into Ransomware's Favorite Region Without that kind of diligent detection, vishing can be highly effective. It bypasses traditional email security protections and leaves fewer footprints behind for cyber defenders to analyze. As an added benefit, victims are less likely to be aware of vishing or practiced at avoiding it. "What they've realized is that there's technical controls in place for email phishing," Adam Meyers, head of counter adversary operations at CrowdStrike, said of vishers in a July 30 press webinar. "We're scanning emails. We've got a whole host of different technologies out there: Proofpoint, Mimecast, Sublime, Abnormal. All of these different products have been built to kind of handle email based phishing attacks." "Targeting humans, targeting the help desk, is way more effective" than technical hacking, he says. With new kinds of phishing mindgames, "You don't have to hack in, you just have to log in." About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like CYBERSECURITY ANALYTICS Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs by Nate Nelson JUL 02, 2026 CYBERSECURITY ANALYTICS In Cybersecurity, Claude Leaves Other LLMs in the Dust by Nate Nelson DEC 17, 2025 CYBERSECURITY ANALYTICS Mideast, African Hackers Target Gov'ts, Banks, Small Retailers by Nate Nelson OCT 23, 2025 CYBERSECURITY ANALYTICS Commentary Section Launches New, More Opinionated Era by Becky Bracken OCT 10, 2025 Black Hat USA Coverage APPLICATION SECURITY AI Harnesses Burst With Potential Exploit Opps byRobert Lemos JUL 30, 2026 4 MIN READ APPLICATION SECURITY When AppSec Scanners Become a Supply Chain Attack Vector byEricka Chickowski JUL 29, 2026 5 MIN READ CYBERSECURITY OPERATIONS Red Agents vs. Blue Agents: How to Make AI Better at Defense byRob Wright JUL 29, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS
    💬 Team Notes
    Article Info
    Source
    Dark Reading
    Category
    ✉ Email Security
    Published
    Aug 04, 2026
    Archived
    Aug 04, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗