Device Code Phishing Up 1,500% in 2026; Vishing Doubles - Dark Reading
Dark ReadingArchived Aug 04, 2026✓ Full text saved
Device Code Phishing Up 1,500% in 2026; Vishing Doubles Dark Reading
Full text archived locally
✦ AI Summary· Claude Sonnet
CYBERSECURITY ANALYTICS
THREAT INTELLIGENCE
ENDPOINT SECURITY
MOBILE SECURITY
NEWS
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
Nate Nelson,Contributing Writer
August 4, 2026
4 Min Read
SOURCE: ABU HANIFAH VIA GETTY IMAGES
Phishing is evolving faster than it has in a long, long time.
Email-based phishing undisputedly has been the most dominant means of social engineering in the 21st century. It hasn't changed much in that time, and attackers followed pretty much the same basic principles, evolving mostly in their efficacy and ease of operation.
In the first half of 2026, though, attackers have been graduating in droves to relatively newer, less obvious phishing techniques. Crowdstrike tracked a doubling of voice phishing (vishing) attacks in this period, according to its newly released 2026 Threat Hunting Report. In the same time period, it tracked a 15-fold increase in device code phishing. Both techniques are helping state-sponsored threat actors and cybercriminal groups bypass traditional security controls.
Device Code Phishing Explodes
On Oct. 13, 2020, the high-profile Microsoft researcher Nestori Syynimaa published a blog post in which he invented the technique now known as device code phishing.
Related:Stronger AI Safety Requires Peeking Inside the 'Black Box'
It took a long time for anyone else to catch on. Only in August 2024 did a Russian nation-state threat actor, tracked by Microsoft as "Storm-2372," have the bright idea to try out Syynimaa's technique in a proper cyberattack campaign. By doing so, it managed to compromise organizations across major industries — government, defense, energy, and others — and broad regions — North America, Europe, Africa, and the Middle East — before Microsoft finally discovered and described it in a public blog post the following year.
Slowly over the course of 2025, the technique trickled down from the Russian state to cybercriminal groups. Multiple research groups independently noticed a steady rise in device code phishing as 2025 went on, most notably by actors associated with Tycoon 2FA, the world's leading phishing operation at the time.
In 2026, device code phishing is becoming mainstream. CrowdStrike observed 15 times more such attacks through the first half of this year than it had through the second half of last. In particular, it noted that attackers are using the technique to compromise cloud identities.
"A diverse set" of cybercriminals is doing it now, CrowdStrike wrote, the most prominent among them being the Russian advanced persistent threat (APT) group known as Cozy Bear. CrowdStrike describes other financially motivated device code phishers as followers of Cozy Bear's model, "deploying dedicated device code and session management infrastructure, leveraging legitimate cloud-based hosting services, and delivering device code phishing pages via Entra ID application OAuth redirection at scale."
Related:Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs
Hackers Choose Vishing for Stealthier Attacks
Vishing was already on the rise going into 2025, and lately its momentum has been accelerating. CrowdStrike measured a 134% increase in vishing from 2024 to 2025. From H2 2025 to H1 2026, vishing rates doubled.
Two of the biggest threat actors utilizing vishing today are tracked by CrowdStrike as "Cordial Spider" and "Snarky Spider." Each uses the technique to ultimately gain access to victims' single sign-on (SSO)-integrated software-as-a-service (SaaS) applications — valuable sources of corporate secrets.
They do it by first directing victims to SSO-themed adversary-in-the-middle (AiTM) pages on their mobile devices. The attackers tailor the phishing pages to the victims they're interested in, and attacking them on their mobile devices often means avoiding the security software victims often install only on their laptop and desktop computers.
Once victims hand over their credentials and multifactor authentication (MFA) codes, the threat actors authenticate and then attempt to register their own MFA devices for persistent access to victims' networks. New device registration is a meaningful early-stage signal defenders look for in these attacks, as CrowdStrike observed in a case back in February. In four minutes flat, Cordial Spider had successfully vished a victim, authenticated to their network, and registered a new allowed MFA device. The new device listing raised alarms, though, alerting the victim and empowering them to boot out their attacker only 12 minutes later.
Related:Europe Evolves Into Ransomware's Favorite Region
Without that kind of diligent detection, vishing can be highly effective. It bypasses traditional email security protections and leaves fewer footprints behind for cyber defenders to analyze. As an added benefit, victims are less likely to be aware of vishing or practiced at avoiding it.
"What they've realized is that there's technical controls in place for email phishing," Adam Meyers, head of counter adversary operations at CrowdStrike, said of vishers in a July 30 press webinar. "We're scanning emails. We've got a whole host of different technologies out there: Proofpoint, Mimecast, Sublime, Abnormal. All of these different products have been built to kind of handle email based phishing attacks."
"Targeting humans, targeting the help desk, is way more effective" than technical hacking, he says. With new kinds of phishing mindgames, "You don't have to hack in, you just have to log in."
About the Author
Nate Nelson
Contributing Writer
Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.
He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.
He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
Prevention at Machine Speed: Hunting Beyond Known Detections
0-Day to 10x Discovery: Security at the Speed of Mythos
When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure
Governing the Agent; Identity Security in the Age of Autonomous AI
More Webinars
You May Also Like
CYBERSECURITY ANALYTICS
Aussies Face Reduced Cybercrime Risk, as Pressure Shifts to SMBs
by Nate Nelson
JUL 02, 2026
CYBERSECURITY ANALYTICS
In Cybersecurity, Claude Leaves Other LLMs in the Dust
by Nate Nelson
DEC 17, 2025
CYBERSECURITY ANALYTICS
Mideast, African Hackers Target Gov'ts, Banks, Small Retailers
by Nate Nelson
OCT 23, 2025
CYBERSECURITY ANALYTICS
Commentary Section Launches New, More Opinionated Era
by Becky Bracken
OCT 10, 2025
Black Hat USA Coverage
APPLICATION SECURITY
AI Harnesses Burst With Potential Exploit Opps
byRobert Lemos
JUL 30, 2026
4 MIN READ
APPLICATION SECURITY
When AppSec Scanners Become a Supply Chain Attack Vector
byEricka Chickowski
JUL 29, 2026
5 MIN READ
CYBERSECURITY OPERATIONS
Red Agents vs. Blue Agents: How to Make AI Better at Defense
byRob Wright
JUL 29, 2026
5 MIN READ
Want more Dark Reading stories in your Google search results?
Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.
SUBSCRIBE
AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS
The premier cybersecurity event returns.
GET YOUR PASS