Surge in Device Code Phishing Attacks: 37-Fold Increase Reported
Cybersecurity experts are sounding the alarm as device code phishing attacks have skyrocketed by over 37 times this year. This alarming trend involves hackers exploiting the OAuth 2.0 Device Authorization Grant flow, tricking victims into granting access to their accounts by entering a code on a legitimate login page.
Many individuals, particularly users of IoT devices, smart TVs, and streaming services, are at risk. The impact of this surge is significant, as it allows attackers to hijack accounts and potentially steal sensitive information.
To protect against these attacks, users are advised to disable device code flows when unnecessary and monitor their accounts for unusual login activities or unauthorized requests.
With the rise in phishing kits like EvilTokens, the risk level for consumers is currently classified as High. Vigilance and proactive security measures are essential to safeguard personal data in this evolving threat landscape.
Source: View Original Report
