Scam emails used to be easy. Bad grammar, weird links, a prince with a wire transfer. Done.
Not anymore. AI just industrialized phishing, and the numbers are wild.
The stat that should scare you
Security firm Huntress tracked a 1,380% jump in a sneaky attack called device-code phishing in early 2026 compared to late last year. That's nearly 15x, in months. (Axios)
Here's the detail that matters: across 344 victim organizations in one wave, no two phishing messages were identical. Every single lure was custom-written, almost certainly by AI. (Huntress)
The old advice "look for typos" is officially dead. AI doesn't make typos.
The scam that beats your MFA
Device-code phishing is nasty because it uses real Microsoft pages. No fake login screen. No sketchy URL.
How it works:
- Attacker generates a legit 8-character device code from Microsoft.
- They send you a convincing message: "IT needs you to re-verify, go to microsoft.com/devicelogin and enter this code."
- You go to the actual Microsoft site, enter the code, approve the MFA prompt.
- The attacker instantly gets a valid access token to your account. (Huntress)
You did everything "right." Real website, real MFA. Still owned. One campaign, dubbed EvilTokens, packaged this whole flow into a subscription service phishing-as-a-service with AI baked in. (Security Boulevard)
Crime, now with a pricing page
That subscription model is the other big shift. Google is suing a China-based operation it calls the "Outsider Enterprise" under RICO, the law built for taking down the mob. The group sold phishing kits starting at $88 a week, with 290+ ready-made website templates, and was linked to 1.59 million fraudulent URLs in about six months. (eSecurity Planet)
Eighty-eight dollars. That's the barrier to entry for running a phishing operation now. And it's not just email, AI-powered scams across texts, QR codes, and voice clones have jumped roughly 14x. (Tech Times)
How to actually protect yourself
Since "spot the typo" is dead, here's what still works:
- Treat unexpected codes as radioactive. No legit IT department cold-messages you a code to enter somewhere. If you didn't start the login, don't finish it.
- Verify through a second channel. Email says it's from IT? Call or Slack IT directly. Voice sounds like your boss asking for a wire transfer? Hang up and call them back on their known number.
- Read the MFA prompt before approving. Device-code phishing needs you to hit approve. If a prompt mentions a device or app you don't recognize, deny it.
- Slow down. Every one of these scams manufactures urgency, "account locked," "verify in 10 minutes." Urgency is the tell now, not grammar.
The takeaway
Phishing stopped being a numbers game of sloppy mass emails. It's now personalized, AI-written, rented by the week, and capable of walking through real login pages. The scams got smarter, your habits have to get smarter too.
Share this with the person in your life who still thinks they can spot a fake email. They probably can't anymore. Neither can you. That's the point.
Sources: Axios, Huntress EvilTokens report, Huntress device-code explainer, Security Boulevard, eSecurity Planet, Tech Times
Photo: Gustavo Fring via Pexels.