Device Code Phishing Surges 1,500% as Attackers Bypass Traditional Security Controls
Cybercriminals are increasingly turning to newer forms of social engineering that slip past conventional security tools, according to recent findings. Device code phishing—a technique that exploits legitimate sign-in processes used by many cloud services—has jumped by an alarming 1,500%, while vishing, or voice phishing, has doubled in frequency.
What makes these methods particularly concerning is their ability to bypass entrenched security controls, such as multi-factor authentication prompts, by tricking users into approving legitimate-looking login requests or manipulating them over the phone. These approaches also tend to leave behind less evidence than traditional phishing emails, making them harder for security teams to detect and investigate after the fact.
For small and medium businesses, this shift matters because it targets the human element rather than technical vulnerabilities. Even organisations with strong technical defences can be compromised if an employee is convinced to approve a fraudulent device login or share sensitive information over a phone call. As attackers refine these tactics, staff awareness and verification habits become just as critical as firewalls and antivirus software.