장치 코드 피싱은 2026년 가장 빠르게 성장하는 위협이다.
장치 코드 피싱은 OAuth 2.0 장치 인증 부여를 악용하여 접근 토큰을 훔치는 공격 방식으로, 6개월 만에 산업 규모의 위협으로 발전했다. 주로 스마트 TV, 프린터와 같은 입력 제약이 있는 장치를 위해 설계된 장치 인증 로그인 흐름이 여러 앱과 사용 사례에 채택되고 있다. 이로 인해 사용자와 기업 모두에게 큰 위험이 되고 있다.
Device code phishing is the fastest-growing threat of 2026.
Device code phishing is a growing threat that exploits OAuth 2.0 device authorization grants to steal access tokens, evolving from a niche tactic to an industrial-scale risk in just six months. It is designed for input-constrained devices like smart TVs and printers and has been adopted by a variety of apps and use cases beyond its original intent. This trend poses significant dangers to both users and businesses.