Device code phishing attacks surge 37x as new kits spread online

2026-04-04T19:23:30Z283ffdd4c118e364c2a2e22f6785d7d92a5b2b8ddd3a15df824b14524232465c
BrowserGateCERT-EUClaude-CodeEuropean-Commission-breachExchange-Online-outageLinkedInProgress-ShareFileQilinStrykerTeamPCPVidarZendeskbrowser-scanningchrome-extensionsdata-breachdata-wipingdevice-code-phishinginfostealeroauth2-device-flowphishing-kitspre-auth-rceproxy-evasionransomwareresidential-proxiessupport-ticket-leak

What happened

Multiple high-impact cyber incidents and attacker trends reported: device-code phishing abusing the OAuth2 Device Authorization Grant has surged ~37x as new phishing kits spread; LinkedIn reportedly runs hidden scripts to scan visitors for 6,000+ Chrome extensions and collect device data ("BrowserGate"); Hims & Hers warns of a data breach after Zendesk support tickets were stolen; Qilin ransomware claims data theft from German party Die Linke; CERT-EU attributes a European Commission cloud hack exposing data of ~30 EU entities to TeamPCP; new Progress ShareFile flaws can be chained for pre‑aut

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
283ffdd4c118e364c2a2e22f6785d7d92a5b2b8ddd3a15df824b14524232465c
Enrichment time
2026-04-04T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Device code phishing attacks surge 37x as new kits spread online · Baitaphish