What is Device Code Phishing?
Device code phishing doesn’t hack its way in. It uses a legitimate authentication flow to walk right through the front door, with no password required, MFA bypassed, and session tokens handed straight to the attacker. The Huntress Security Operations Center (SOC) caught it hitting more than 340 organizations in a matter of weeks and immediately cut off the attackers’ access across every partner environment they could reach.
Shady? Absolutely. Rare? Not even close. Hit play to see exactly how it works and better defend your identities.
“Identity used to be about passwords and MFA. In the cloud, it’s sessions, tokens, and apps — and that’s where most teams are behind.”
– Jenko Hwong, Principal Product Researcher, Identity Threat Detection and Response (ITDR)
Read the ebook on AI-powered adversary tradecraft
Device code phishing demonstrates how attackers can make malicious activity look like a normal authentication step. The ebook explores how AI makes these trusted-workflow attacks more personalized, scalable, and difficult to recognize.