Device Code Phishing Up 1,500% in 2026; Vishing Doubles
BLUF
Social engineering attacks are evolving to bypass security controls while leaving minimal forensic evidence.
NEWS
Dark Reading reports a 1,500% increase in device code phishing and a doubling of vishing incidents in 2026. Attackers are utilizing these newer techniques to ignore entrenched security controls and limit the evidence they leave behind.
Why I Care
Traditional defenses like email filters and standard MFA may fail against these human-centric attacks, increasing the risk of credential theft and unauthorized access. The reduced evidence trail makes detection and incident response significantly harder for security teams.
Next Steps
Security teams must update phishing simulations to include device code scenarios and conduct vishing awareness training for all staff immediately. IT administrators should audit authentication logs for suspicious device code activity and enforce stricter conditional access policies by the end of this quarter.
Source: Dark Reading ·
