Phishing Tactics Evolve, Leaving Security Controls Behind
In a dramatic escalation of social engineering tactics, device code phishing has skyrocketed by 15-fold in the first half of 2026, while voice phishing (vishing) has doubled in the same period. These newer techniques are allowing state-sponsored threat actors and cybercriminal groups to bypass traditional security controls and limit the evidence they leave behind.
Device code phishing, a method invented by Microsoft researcher Nestori Syynimaa in 2020, involves sending malicious device codes to victims via email or messaging apps. The technique was initially used by nation-state threat actors, but has since trickled down to cybercriminal groups. In 2026, it’s becoming increasingly mainstream, with CrowdStrike observing a significant surge in attacks through the first half of the year.
Attackers are using device code phishing to compromise cloud identities and gain access to sensitive corporate secrets. According to CrowdStrike, a “diverse set” of cybercriminals is now using this technique, including the Russian advanced persistent threat (APT) group Cozy Bear. Other financially motivated groups are following Cozy Bear’s model, deploying dedicated infrastructure and leveraging legitimate cloud-based hosting services.
Meanwhile, vishing has also seen a significant increase in 2026, with CrowdStrike measuring a doubling of attacks from H2 2025 to H1 2026. This technique involves tricking victims into divulging sensitive information over the phone. Two prominent threat actors using vishing today are tracked by CrowdStrike as “Cordial Spider” and “Snarky Spider,” which use the method to gain access to single sign-on (SSO)-integrated software-as-a-service (SaaS) applications.
Both device code phishing and vishing allow attackers to avoid traditional security controls, such as antivirus software and firewalls. By using these newer tactics, threat actors can limit the evidence they leave behind, making it more difficult for defenders to detect and respond to attacks.
The implications of this evolution in social engineering tactics are significant. Organizations must be prepared to adapt their defenses to counter these new threats. This includes implementing robust security controls that can detect and prevent device code phishing and vishing attempts. Additionally, employees should be educated on the risks associated with these newer techniques and how to identify suspicious activity.
In conclusion, the rise of device code phishing and vishing represents a significant escalation in social engineering tactics. As threat actors continue to evolve and adapt their methods, it’s essential that organizations stay vigilant and proactive in defending against these new threats. By doing so, they can minimize the risk of successful attacks and protect sensitive corporate secrets from falling into the wrong hands.
Source: Dark Reading — 2026-08-04