Executive Summary
In the first half of 2026, CrowdStrike observed a 1,500% increase in device code phishing attacks and a doubling of voice phishing (vishing) incidents. Device code phishing, initially identified in 2020, gained traction among Russian state-sponsored actors by 2024 and has since been adopted by various cybercriminal groups. These attackers exploit device code authentication flows to compromise cloud identities, often bypassing traditional security measures. Concurrently, vishing campaigns have become more sophisticated, with threat actors like 'Cordial Spider' and 'Snarky Spider' targeting single sign-on (SSO) integrated SaaS applications. By directing victims to adversary-in-the-middle (AiTM) pages on mobile devices, these attackers circumvent conventional email security controls, facilitating unauthorized access to sensitive corporate data. The rapid adoption and evolution of these social engineering techniques underscore the need for organizations to enhance their security awareness training and implement robust multi-factor authentication mechanisms to mitigate the risks associated with these emerging threats.
Why This Matters Now
The significant rise in device code phishing and vishing attacks in 2026 highlights the evolving tactics of cyber adversaries who are leveraging these methods to bypass traditional security controls. Organizations must prioritize updating their security protocols and employee training to address these sophisticated social engineering techniques effectively.
Attack Path Analysis
Attackers initiated the campaign by sending phishing messages via third-party messaging services, tricking users into entering device codes on legitimate Microsoft authentication pages. Upon obtaining valid authentication tokens, they escalated privileges by accessing sensitive data and services within the compromised accounts. The attackers then moved laterally by leveraging the compromised accounts to access additional resources and services. They established command and control by maintaining persistent access through the use of refresh tokens and malicious inbox rules. Data exfiltration was conducted by harvesting emails and other sensitive information from the compromised accounts. The impact included unauthorized access to confidential information, potential financial loss, and reputational damage to the affected organizations.
Kill Chain Progression
Initial Compromise
Description
Attackers sent phishing messages via third-party messaging services, tricking users into entering device codes on legitimate Microsoft authentication pages.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Spearphishing Link
Valid Accounts
Brute Force
Web Protocols
File Transfer Protocols
Mail Protocols
DNS
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing vulnerabilities are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14(b)
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity risk-management measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Device code phishing and vishing attacks specifically target SSO-integrated SaaS applications containing corporate secrets, bypassing traditional email security controls in financial institutions.
Government Administration
Russian nation-state actors like Storm-2372 and Cozy Bear actively compromise government organizations using device code phishing to access cloud identities and sensitive systems.
Oil/Energy/Solar/Greentech
Energy sector faces targeted device code phishing campaigns from state-sponsored groups, with attacks increasing 1,500% and bypassing conventional cybersecurity defenses through social engineering.
Defense/Space
Defense organizations are prime targets for Russian APT groups using evolved phishing techniques to compromise cloud identities and access classified information systems globally.
Sources
- Device Code Phishing Up 1,500% in 2026; Vishing Doubleshttps://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doublesVerified
- 2026 CrowdStrike Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surfacehttps://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/Verified
- A new vishing campaign is targeting Microsoft Teams - here's what users need to knowhttps://www.itpro.com/security/phishing/a-new-vishing-campaign-is-targeting-microsoft-teams-heres-what-users-need-to-knowVerified
- Exclusive: Phishing enters automation erahttps://www.axios.com/2026/06/23/ai-automation-phishing-emails-hackersVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can significantly limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could potentially limit the attacker's ability to exploit compromised credentials by enforcing strict identity-aware policies.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls based on identity and workload segmentation.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely constrain the attacker's lateral movement by enforcing strict segmentation and monitoring of internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the attacker's ability to establish and maintain command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely constrain the attacker's ability to exfiltrate data by enforcing strict outbound traffic policies and monitoring.
Aviatrix Zero Trust CNSF would likely reduce the overall impact of the attack by limiting the attacker's ability to access and exfiltrate sensitive data through strict segmentation and identity-aware policies.
Impact at a Glance
Affected Business Functions
- User Authentication Systems
- Email Communication
- Cloud Service Access
- Customer Support Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of user credentials, including usernames and passwords, leading to unauthorized access to sensitive systems and data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement by enforcing least privilege access controls.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to unusual authentication patterns and access behaviors.
- • Utilize Multicloud Visibility & Control to monitor and manage access across all cloud environments, ensuring consistent policy enforcement.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration by monitoring and controlling outbound traffic.
- • Apply Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads in network traffic.



