IAMRoadmapIAMRoadmap
INDUSTRY TRENDS

IAM News: Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapi

2 min readAugust 5, 2026IAM Roadmap Team

Key Insight

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishi...

📰 Source: The Hacker News

Summary

The commercial phishing-as-a-service (PhaaS) toolkit Greatness has added support for device code phishing, a rapidly growing cyber threat that bypasses Multi-Factor Authentication (MFA) and steals user tokens. This development enables attackers to exploit the OAuth 2.0 Device Authorization Grant, further compromising user account security. The rise of PhaaS and device code phishing poses significant challenges to identity and access management (IAM) professionals.

Attack Flow

Uses PhaaS

Generates Phishing Page

User Enters Credentials

Attacker Steals Token

Attacker

Greatness PhaaS

Phishing Page

User Device

Target System

IAM Impact

The addition of device code phishing support in Greatness PhaaS significantly impacts IAM in several ways:

  • MFA Bypass: Attackers can now bypass MFA by exploiting the OAuth 2.0 Device Authorization Grant, making it essential for organizations to reevaluate their MFA strategies.
  • Token Theft: The theft of user tokens compromises account security and increases the risk of unauthorized access to sensitive data and systems.
  • Increased Phishing Threat: The rise of PhaaS and device code phishing heightens the threat of phishing attacks, requiring IAM professionals to develop more effective countermeasures.

Key Takeaways

  • Device Code Phishing is a Growing Threat: The addition of device code phishing support in Greatness PhaaS underscores the importance of staying informed about emerging threats and adapting IAM strategies accordingly.
  • MFA Must be Implemented Correctly: Organizations must ensure that MFA is properly configured and that users understand how to use it effectively to prevent bypass attempts.
  • User Education is Crucial: Educating users about the risks of phishing and the importance of verifying the authenticity of login pages can help prevent successful attacks.

Recommendations

  • Review and Update MFA Policies: Organizations should reassess their MFA policies and procedures to ensure they are effective against device code phishing attacks.
  • Implement Additional Security Measures: Consider implementing additional security measures, such as behavioral analytics and machine learning-based threat detection, to enhance IAM defenses.
  • Provide User Education and Awareness: Offer regular training and awareness programs to educate users about phishing threats and the importance of verifying login pages to prevent successful attacks.
Trend Topics
IAM newssecurity newsThe Hacker News
All Articles