Return to Threats

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

thehackernews.com 2026-08-04 malicious AI use Critical

What Happened

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. "Greatness supports AiTM [adversary-in-the-middle] credential and

Why It Matters

The article reports that the commercial Greatness phishing-as-a-service kit now supports device code phishing, abusing the legitimate OAuth 2.0 Device Authorization Grant to bypass MFA and steal access and refresh tokens across platforms like Microsoft 365, Google Workspace, iCloud, and Yahoo.[1][3][5][8] It also bundles AiTM token theft and OAuth consent abuse in a low-skill operator panel, enabling widespread, turnkey identity compromise for criminal affiliates.[1][3][4] From a RealGround perspective, this represents malicious automation of identity attacks that can be integrated into or target AI-enabled systems and agents, increasing the risk of unauthorized access to AI workloads, data, and model APIs via stolen tokens. Organizations should treat device-code and token-based phishing as a core scenario in their AI threat models and use continuous AI red teaming to simulate token theft, validate Conditional Access controls (e.g., blocking device code flow where not needed), and ensure AI agents and back-end services correctly handle compromised identities and sessions.[3][6][10][18]

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html

Talk to AI CISO