Skip to content
Emerging Threat of Authorization Phishing in 2026

Emerging Threat of Authorization Phishing in 2026

First seen 30 Sep 2026, 17:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 18:35 UTC
  • •Authorization phishing targets OAuth consent flows post-authentication.
  • •Over 30 distinct device code phishing kits are now available to attackers.
  • •Security teams must adapt to evolving phishing tactics to protect against these threats.

In 2026, a new class of phishing attacks known as authorization phishing has gained traction, targeting the OAuth consent flow after users have already authenticated. Attackers leverage device code phishing techniques to bypass traditional authentication controls, including MFA and phishing-resistant passkeys. This shift in tactics reflects a broader trend as attackers adapt to improved security measures. The rise of authorization phishing is evidenced by over 30 distinct kits now available, with ConsentFix being a notable tool that has been commoditized for criminal use. Security teams are urged to enhance their detection capabilities to combat these evolving threats. The articles highlight that while traditional phishing methods remain prevalent, the focus is shifting towards exploiting authorization layers, making it for organizations to stay vigilant.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
Authorization phishing identified as a new threat
Push Security reports a significant rise in authorization phishing attacks targeting OAuth mechanisms.
pushsecurity.com
2026-09-30
Device code phishing kits proliferate
The number of distinct device code phishing kits has surpassed 30, indicating a growing trend in phishing techniques.
Thehackernews

More articles in this cluster (3)

Following this threat?

Track Apt29, ClickFix and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is authorization phishing?
Authorization phishing targets the OAuth consent mechanisms after a user has already authenticated, allowing attackers to gain access tokens without stealing credentials.
How can we detect authorization phishing?
Organizations should enhance their detection capabilities by monitoring OAuth consent flows and implementing behavioral analysis to identify unusual activity.
What tools are being used for these attacks?
Attackers are utilizing various device code phishing kits, with ConsentFix being a notable example that has been commoditized for criminal use.