Rank 10Identity attacks
AI-enabled device-code phishing
Attackers combine device-code abuse with AI-assisted social engineering to obtain authenticated sessions without stealing a conventional password.
- Momentum score
- 73
- Impact
- High
- Confidence
- High
Why it is rising
Microsoft described a 2026 campaign as an escalation from device-code phishing activity first observed in 2025.
Six-month trajectory
Normalized weekly momentum for prototype validation
+15 over 4 weeks
Six months agoCurrent week
Marketing implications
High-level suggestions for buyer education. These are not claims that a product would have prevented a reported incident.
- 01Move the phishing conversation beyond passwords to token and session abuse.
- 02Explain which access policies reduce exposure to device-code consent attacks.
- 03Create buyer education on verifying authentication prompts generated outside normal workflows.