Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know.
As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.
July 27, 2026
The surge in device-code phishing attacks highlights how threat actors are increasingly stealing passwords to target authentication sessions, tokens, and trust relationships that enable them to masquerade as legitimate users and maintain persistent access.
Compromised tokens and sessions allow attackers to operate within trusted identity environments, making malicious activity indistinguishable from legitimate user behavior. Device code phishing, for instance, exploits a legitimate sign-in process designed for devices with limited input capabilities, such as smart TVs or IoT devices. Attackers trick users into entering a code from a phishing email into a real Microsoft or Google authentication page, unknowingly authorizing the attacker's session and granting account access. These attacks succeed even in environments with multi-factor authentication (MFA) enabled because they target authenticated sessions rather than passwords themselves.









