Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-augmented phishing, device code abuse, and OAuth sprawl


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Identity compromise in Scattered Spider-style attacks is dominating roughly 70% of browser and identity-related breaches, while device code phishing, OAuth supply chain abuse, and AI-assisted phishing kits are spreading fast across SaaS and cloud access paths, according to Push Security. The real shift is that attackers now industrialize familiar identity abuses faster than IAM and browser controls can adapt.

NHIMG editorial — based on content published by Push Security: PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling in the 2026 threat landscape

By the numbers:

Questions worth separating out

Q: How should security teams defend against device code phishing in SaaS environments?

A: Treat device-code entry as an authorization event, not a benign login step.

Q: Why do OAuth tokens increase lateral movement risk in SaaS environments?

A: OAuth tokens increase lateral movement risk because they can remain valid after the initial user session, bypass MFA, and preserve scoped access until revoked.

Q: What do security teams get wrong about AI-powered phishing?

A: They often overestimate human ability to spot deception.

Practitioner guidance

  • Harden device-code authorization flows Restrict device code usage to the minimum set of applications and user groups, and log every grant as a high-risk authorization event.
  • Inventory and review delegated OAuth access Build a register of third-party apps, stored refresh tokens, and vendor-held OAuth grants across SaaS platforms.
  • Treat help-desk impersonation as an identity attack path Update service desk procedures so passkey setup, account reset, and MFA re-registration requests require stronger verification and callback validation.

What's in the full article

Push Security’s full analysis covers the operational detail this post intentionally leaves for the source:

  • Per-kit detection patterns for AiTM, device code phishing, and ClickFix campaigns across real-world infrastructure
  • Examples of browser-layer telemetry that distinguishes credential relay from ordinary user activity
  • Observed abuse patterns across OAuth supply chain attacks, including downstream token propagation
  • Implementation detail on how the vendor detects phishing behavior at the browser layer

👉 Read Push Security’s threat landscape update on AI-augmented phishing and identity abuse →

AI-augmented phishing, device code abuse, and OAuth sprawl?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Identity compromise has become the default enterprise breach path. The report’s 70% figure for SLH-affiliated browser and identity-related breaches is not a noisy outlier, it is evidence of market convergence around identity as the easiest route to scale. That means attackers are optimizing for trust paths, not technical novelty. For practitioners, identity governance must now assume that phishing, token theft, and delegation abuse are the normal case, not edge cases.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.

A question worth separating out:

Q: Who is accountable when SaaS access persists after a tool is no longer needed?

A: Accountability sits with the business owner, the application owner, and the identity governance team together. If any one of them assumes someone else will remove access, the entitlement can remain active long after the business use case ends. Lifecycle control must be assigned before the tool is put into production.

👉 Read our full editorial: AI-augmented phishing and OAuth abuse are reshaping identity risk



   
ReplyQuote
Share: