Oh, I use MFA!

September 16, 2026

Oh, I use MFA!

Passkeys were supposed to end phishing. A technique called device code phishing proves they didn’t, it just moved the attack to a layer nobody was watching.

For years, the advice was simple: turn on MFA, and better yet, switch to passkeys, and phishing stops working. That advice just quietly stopped being true. Device code phishing, a technique that abuses a legitimate OAuth feature rather than stealing a password, has exploded from a niche, state-linked tool into a commodity criminal kit in under a year. Push Security measured a 37.5x rise in device code phishing pages in the first four months of 2026 alone. Huntress tracked a 1,380% jump in detections, with 344 organizations hit in a single wave by one phishing as-a-service kit called EvilTokens. Barracuda logged over 7 million attempts in a single four week stretch. At least 18 separate phishing kits now ship the technique as a standard feature.

Why Passwords and Passkeys Don’t Stop This

Device code phishing doesn’t try to steal a password or spoof a login page. It abuses the OAuth 2.0 device authorization grant, a legitimate feature built for devices without a normal browser, like a smart TV or CLI tool, so a user can sign in elsewhere and approve access with a short code. Attackers send a lure, often disguised as a document, voicemail, or the now-common “verify you’re human” ClickFix prompt, that walks the victim through entering a code on the real Microsoft or provider login page. The victim signs in on the genuine site and completes MFA for real. Nothing about the login is fake. The session token that gets issued afterward, however, lands on the attacker’s device instead of the victim’s. Since the attack targets authorization rather than authentication, it does not matter whether the victim used a password, an authenticator app, or a hardware passkey. All of them satisfy a login that was never actually theirs to approve. The numbers show why this matters beyond one clever technique. Proofpoint found that 59% of accounts taken over in 2026 had MFA enabled at the time. Obsidian Security reported that MFA failed to stop the attacker in 84% of the incidents it responded to. IBM’s 2026 Cost of a Data Breach Report puts phishing as the most expensive breach entry point at an average of $5.29 million. The control isn’t broken. Attackers simply stopped attacking it.

Closing the Gap CYBRT Sees Most Often

Most identity programs are built to strengthen the login screen: password complexity, MFA enforcement, and increasingly, passkeys. Very few are built to monitor what happens after login succeeds, which is exactly where this technique lives. This is the gap GRC and identity risk assessments increasingly need to test for directly rather than assume is covered, and it’s where firms like CYBRT are helping organizations across the Gulf move identity security past a login-screen checklist:
• Restrict or block the OAuth device code flow through Conditional Access policies wherever it isn’t operationally required, since Microsoft itself now recommends disabling it by default.
• Treat session tokens as credentials, with shorter token lifetimes and token-binding controls, so a stolen session can’t be replayed indefinitely.
• Monitor for device code sign-ins from users or applications that never use them, and for refresh-token activity originating from unfamiliar locations.
• Test staff against real device code and ClickFix-style lures, not just generic phishing templates, since the victim experience here looks completely legitimate.
• Build revocation into the incident response playbook, so a suspected compromise triggers an immediate refreshtoken revocation, not just a password reset.

The Takeaway

Phishing-resistant MFA and passkeys were a genuine step forward, and they still stop the attacks they were designed for.But security built entirely around the login screen leaves the authorization layer wide open, and attackers noticed faster than most identity programs adapted. The real question isn’t whether your organization enforces strong authentication.It’s whether anyone would notice if a session token walked out the back door instead.

Ready To Protect Your Business?

Book your free security consultation today