Cybercriminals are pivoting away from traditional email phishing toward more sophisticated methods like device code phishing and vishing. New reports show a massive 15-fold spike in device code attacks in early 2026.
Key Takeaways
- Device code phishing has seen a massive 1,500% increase in the first half of 2026.
- Voice phishing (vishing) attacks have doubled compared to previous periods.
- Attackers are bypassing traditional email security by targeting human psychology and mobile devices.
- State-sponsored actors like Cozy Bear are driving these advanced methodologies.
The landscape of social engineering is undergoing a seismic shift. While email-based phishing has dominated the 21st century, the first half of 2026 has signaled the era of more elusive techniques. According to the CrowdStrike 2026 Threat Hunting Report, attackers are graduating to methods that leave minimal footprints and bypass entrenched security controls.
The Explosion of Device Code Phishing
One of the most alarming trends is the 15-fold increase in device code phishing. Originally a concept highlighted by researchers, this technique has moved from the hands of elite nation-state actors—such as the Russian group Storm-2372—into the mainstream cybercriminal toolkit. These attackers leverage legitimate cloud-based hosting and OAuth redirection to compromise high-value cloud identities.
Why This Matters
BozokMedia analysis shows that these evolving tactics are specifically designed to circumvent the massive investments companies have made in email security filters. By shifting the battlefield from the inbox to cloud authentication flows, attackers are finding a path of least resistance.
"You don't have to hack in, you just have to log in." — Adam Meyers, CrowdStrike.
Vishing: The Stealthy Mobile Threat
Alongside device code phishing, vishing (voice phishing) has doubled in prevalence. Threat actors like 'Cordial Spider' and 'Snarky Spider' are utilizing mobile-centric attacks. Because many corporate security tools are primarily installed on desktops and laptops, mobile devices remain a vulnerable entry point. Attackers use vishing to trick users into handing over credentials and Multi-Factor Authentication (MFA) codes, often registering their own devices to the network within minutes.
Frequently Asked Questions
Question 1: What makes device code phishing so effective?
It exploits the way users authorize devices on cloud services, allowing attackers to hijack sessions without needing a traditional password.
Question 2: How can organizations defend against vishing?
Organizations should implement strict identity verification protocols for help desks and train employees to be skeptical of unsolicited voice communications.