TL;DR: Identity compromise in Scattered Spider-style attacks is dominating roughly 70% of browser and identity-related breaches, while device code phishing, OAuth supply chain abuse, and AI-assisted phishing kits are spreading fast across SaaS and cloud access paths, according to Push Security. The real shift is that attackers now industrialize familiar identity abuses faster than IAM and browser controls can adapt.
NHIMG editorial — based on content published by Push Security: PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling in the 2026 threat landscape
By the numbers:
- Of the browser and identity-related breaches we've tracked, SLH-affiliated groups are responsible for roughly 70% . Public breaches and campaigns with a browser and identity-related breach vector in 2026.
- We saw a huge spike in device code phishing since the start of 2026, with 25+ distinct kits now offering the technique.
- Sekoia documented the ErrTraffic MaaS platform achieving a 60% victim conversion rate.
Questions worth separating out
Q: How should security teams defend against device code phishing in SaaS environments?
A: Treat device-code entry as an authorization event, not a benign login step.
Q: Why do OAuth tokens increase lateral movement risk in SaaS environments?
A: OAuth tokens increase lateral movement risk because they can remain valid after the initial user session, bypass MFA, and preserve scoped access until revoked.
Q: What do security teams get wrong about AI-powered phishing?
A: They often overestimate human ability to spot deception.
Practitioner guidance
- Harden device-code authorization flows Restrict device code usage to the minimum set of applications and user groups, and log every grant as a high-risk authorization event.
- Inventory and review delegated OAuth access Build a register of third-party apps, stored refresh tokens, and vendor-held OAuth grants across SaaS platforms.
- Treat help-desk impersonation as an identity attack path Update service desk procedures so passkey setup, account reset, and MFA re-registration requests require stronger verification and callback validation.
What's in the full article
Push Security’s full analysis covers the operational detail this post intentionally leaves for the source:
- Per-kit detection patterns for AiTM, device code phishing, and ClickFix campaigns across real-world infrastructure
- Examples of browser-layer telemetry that distinguishes credential relay from ordinary user activity
- Observed abuse patterns across OAuth supply chain attacks, including downstream token propagation
- Implementation detail on how the vendor detects phishing behavior at the browser layer
👉 Read Push Security’s threat landscape update on AI-augmented phishing and identity abuse →
AI-augmented phishing, device code abuse, and OAuth sprawl?
Explore further
Identity compromise has become the default enterprise breach path. The report’s 70% figure for SLH-affiliated browser and identity-related breaches is not a noisy outlier, it is evidence of market convergence around identity as the easiest route to scale. That means attackers are optimizing for trust paths, not technical novelty. For practitioners, identity governance must now assume that phishing, token theft, and delegation abuse are the normal case, not edge cases.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when SaaS access persists after a tool is no longer needed?
A: Accountability sits with the business owner, the application owner, and the identity governance team together. If any one of them assumes someone else will remove access, the entitlement can remain active long after the business use case ends. Lifecycle control must be assigned before the tool is put into production.
👉 Read our full editorial: AI-augmented phishing and OAuth abuse are reshaping identity risk