Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Phishing Attacks Evolve: Device Code Phishing Soars 1,500% in 2026, Vishing Doubles

Cybersecurity experts have been warning about the increasing threat of phishing attacks for years. However, in 2026, a new wave of sophisticated phishing techniques is making it even harder for organizations to stay safe. A recent report by CrowdStrike reveals that device code phishing has skyrocketed 1,500% in the first half of this year, while vishing (voice phishing) has doubled.

At its core, phishing involves tricking individuals into revealing sensitive information or clicking on malicious links. However, traditional email-based phishing is becoming less effective as more people become aware of the risks and take precautions such as using strong passwords and enabling two-factor authentication (2FA). As a result, attackers are turning to newer techniques that allow them to bypass entrenched security controls and limit the evidence they leave behind.

One such technique is device code phishing, which was first identified by Microsoft researcher Nestori Syynimaa in 2020. The method involves sending victims a malicious link or attachment that contains device code – essentially a set of instructions that can be used to gain access to an organization’s systems. This type of attack is particularly effective because it allows attackers to compromise cloud identities, which are often not protected by traditional security controls.

CrowdStrike has observed a 15-fold increase in device code phishing attacks through the first half of this year, with Cozy Bear, a Russian advanced persistent threat (APT) group, being one of the most prominent actors. The group is using sophisticated tactics to deploy device code and session management infrastructure, leveraging legitimate cloud-based hosting services and delivering malicious pages via OAuth redirection at scale.

Vishing, which involves attackers calling victims directly to trick them into revealing sensitive information, has also seen a significant surge in 2026. CrowdStrike measured a 134% increase in vishing from 2024 to 2025, with rates doubling from the second half of last year to the first half of this year. Two threat actors, tracked by CrowdStrike as “Cordial Spider” and “Snarky Spider,” are using vishing to gain access to victims’ single sign-on (SSO)-integrated software-as-a-service (SaaS) applications.

To protect themselves from these evolving threats, organizations need to be more vigilant than ever. This means keeping security software up-to-date, educating employees about the risks of phishing and vishing, and implementing robust authentication protocols that go beyond traditional passwords and 2FA. By staying ahead of the curve and adapting to new threats as they emerge, organizations can reduce their risk of falling victim to these sophisticated attacks.

Ultimately, the rise of device code phishing and vishing underscores the need for a more proactive approach to cybersecurity. As attackers become increasingly sophisticated in their tactics, it’s essential that organizations stay one step ahead by investing in robust security measures, conducting regular threat hunting exercises, and staying informed about emerging threats. By doing so, they can protect themselves from the evolving threats of phishing and vishing, and keep their sensitive data and systems safe.


Source: Dark Reading — 2026-08-04