Hacking Humans · N2K Networks

When legit is the trick: Phishing’s sneaky new moves. [OMITB]

February 3, 2026·40 min·3 clips
Device code phishing defeats every anti-phishing rule you've been taught — the URL is real, the MFA is real, and you still get owned.
Cyber Feud comes in sideways. Dave turns malware symptoms into a game-show bit, with Selena calling out slow performance and Keith grabbing pop-ups as the next answer. The joke keeps building: antivirus panic, homepage changes, webcam lights, all the stuff that makes people mutter about malware. Then the point gets quieter and more useful. The later conversation shifts to phishing that is not really chasing the username and password. The thing worth stealing is the token. That changes what good defense looks like. One speaker says the cleanest move, when an organization can do it, is to block device code phishing outright. Lock down that path and the flow should fail, even if someone follows the prompt and gets as far as the device code. Conditional access gets the less flashy job. Treat access more like an allow list: known apps, known users, operating systems, IP ranges, and named locations. Russia is the simple example. If a login appears from somewhere the organization does not expect, the policy should make it look wrong quickly. Training still has work to do. The catch is that normal suspicious-URL advice cannot carry the whole lesson, because the user may be nudged into an action that looks legitimate. Teach the action, not just the screenshot. The useful bit is why the move works socially, why someone might comply, and which exact request should make them stop. After that, the show turns corporate again. Credits, review asks, and a ThreatLocker sponsor read land after the security lesson, so the clip boundary is easy to spot.

As heard by us

A practical look at device code phishing, where a legitimate login flow becomes the attack path.

Device code phishing lands here as a tidy example of a grim security truth: legitimate login flows can become the trick. The attacker is not chasing the username and password so much as the token, and the episode is clearest when it stays on that distinction.

Read the full review in PlayNext →

Why you'd press play

Need a clear take on device-code phishing without the webinar theater?

Read the full recommendation in PlayNext →
Listen to the show on