Reporting on the campaign running through 2025 into 2026 describes device code phishing as a core method, with more than a thousand organisations compromised and 1.5 billion records claimed.
The organisation count is the figure worth attending to. The record claim originates with the group, describes deduplication nobody can check, and is exactly the sort of number a leak site publishes to be quoted.
Consent Scales In A Way Exploitation Does Not
An exploit-driven campaign is bounded by the vulnerable population and decays as patches roll out. A consent-driven campaign has no such ceiling. There is nothing to patch, the technique works identically against every tenant, and its effectiveness depends on human behaviour rather than software version.
It is also cheap to industrialise. Once the call script works, the constraint is calling capacity, and reporting describes exactly that division of labour — social engineering capability paired with automated extraction tooling.
Why The Defensive Advice Keeps Failing
The standard guidance is to train users to recognise the call. That has been the guidance for years, against a technique whose success rate has not visibly declined, aimed at people whose job requires cooperating with IT requests under time pressure.
The controls that actually bound this are architectural rather than educational: restrict who may authorise applications, restrict which applications may be authorised, alert on new grants, and give refresh tokens a lifetime. All of them reduce someone’s convenience, which is why they remain uncommon.
Compiled from public reporting, listed below. The 1.5 billion record figure and the organisation count originate with the attacking group; we reproduce them as claims and do not treat them as established. Corrections: corrections@forensicpost.com.