SECURITYTHE HACKER NEWS
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, which exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal user tokens. This method allows attackers to seize control of accounts by leveraging a legitimate authentication protocol.
Mentioned
Related Signal
Adjacent reporting
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
- The New Phishing Click: How OAuth Consent Bypasses MFA
- Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing
- Webinar: How attackers bypass MFA and how defenders can respond
- When attackers already have the keys, MFA is just another door to open
- Device Code Phishing Up 1,500% in 2026; Vishing Doubles