---
title: "Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens | SpinGraph: Threat normalization"
description: "SpinGraph analysis of The Hacker News's Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens story: threat normalization, The Fog, Spin Sco…"
	canonical: "https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens"
html: "https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens"
json: "https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens.json"
markdown: "https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens.md"
keywords: ["device code phishing", "OAuth 2.0", "MFA bypass", "The Fog", "narrative intelligence"]
date: "2026-08-04T17:27:39+00:00"
modified: "2026-08-04T19:21:49.027138+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens#article","headline":"Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens","alternativeHeadline":"Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens | SpinGraph: Threat normalization","description":"SpinGraph analysis of The Hacker News's Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens story: threat normalization, The Fog, Spin Sco…","datePublished":"2026-08-04T17:27:39+00:00","dateModified":"2026-08-04T19:21:49.027138+00:00","url":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"device code phishing, OAuth 2.0, MFA bypass, PhaaS, AiTM","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html","about":[{"@type":"Thing","name":"device code phishing"},{"@type":"Thing","name":"OAuth 2.0"},{"@type":"Thing","name":"MFA bypass"},{"@type":"Thing","name":"PhaaS"},{"@type":"Thing","name":"AiTM"},{"@type":"Product","name":"Greatness","url":"https://stuffthatspins.com/entities/greatness"},{"@type":"Thing","name":"OAuth 2.0 device authorization grant","url":"https://stuffthatspins.com/entities/oauth-20-device-authorization-grant"}],"mentions":[{"@type":"Organization","name":"The Hacker News"}],"abstract":"Greatness, a commercial phishing-as-a-service (PhaaS) platform, now supports device code phishing. This technique abuses OAuth 2.0’s legitimate Device Authorization Grant flow to circumvent multi-factor authentication. It enables adversaries to steal session tokens and gain persistent access without triggering MFA prompts."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens","item":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens#spin-analysis","headline":"Spin Analysis: threat normalization","description":"Emphasizes technical novelty and protocol abuse while minimizing evidence of actual deployment, victim impact, or defensive countermeasures; omits vendor-specific context, detection rates, or forensic artifacts.","about":{"@type":"DefinedTerm","name":"threat normalization","description":"Technical threat bulletin — positioning the story as objective, timely, and authoritative reconnaissance on evolving adversary tradecraft.","termCode":"The Fog"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":40,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Greatness PhaaS now supports device code phishing to bypass MFA via OAuth 2.0."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Technical threat bulletin — positioning the story as objective, timely, and authoritative reconnaissance on evolving adversary tradecraft."},{"@type":"PropertyValue","name":"Missing Context","value":"No data on observed campaigns, victim sectors, or time-to-detection metrics; No mention of whether this capability has been observed in active intrusions; No discussion of mitigations beyond generic OAuth hygiene"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as rapidly growing cyber threat, seize control, bypass. The distribution reads as editorial reporting. A pressure point: No data on observed campaigns, victim sectors, or time-to-detection metrics."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.","appearance":"The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing... to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"crimeware adoption status","value":"latest","description":"Positioned as the most recent PhaaS to integrate this capability"}]}]}
---

# Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

**Source:** Unknown  
**Published:** August 4, 2026  
**Original:** https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

The Greatness PhaaS toolkit added device code phishing capabilities to exploit OAuth 2.0’s Device Authorization Grant and bypass MFA, enabling credential theft and account takeover.

### TL;DR

- Greatness, a commercial phishing-as-a-service (PhaaS) platform, now supports device code phishing.
- This technique abuses OAuth 2.0’s legitimate Device Authorization Grant flow to circumvent multi-factor authentication.
- It enables adversaries to steal session tokens and gain persistent access without triggering MFA prompts.

### Key Stats

- **latest** — crimeware adoption status. Positioned as the most recent PhaaS to integrate this capability

<a id="spingraph"></a>

## SpinGraph

The article presents a newly added feature in criminal software as if it's already part of the live threat landscape — making it feel urgent and inevitable, even though we don’t know how often it’s used or how effective it really is.

- **Claim:** Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA)
- **Frame:** Key details stay obscured
- **Beneficiary:** Enhanced credibility as frontline observers of crimeware innovation
- **Gap:** No data on observed campaigns, victim sectors, or time-to-detection metrics
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 40%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** signal_momentum  

### The Spin in Plain English

The article presents a newly added feature in criminal software as if it's already part of the live threat landscape — making it feel urgent and inevitable, even though we don’t know how often it’s used or how effective it really is.

**What the story wants you to believe:** Device code phishing is now a commoditized, production-ready capability in commercial crimeware toolkits.  

**What it makes harder to question:** Whether this capability is functionally mature, widely deployed, or materially more dangerous than existing AiTM or credential harvesting techniques.  

**How the Spin Works:** The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as rapidly growing cyber threat, seize control, bypass. The distribution reads as editorial reporting. A pressure point: No data on observed campaigns, victim sectors, or time-to-detection metrics.  

### Questions This Story Raises

- What concrete evidence supports the momentum claim?
- Is this growth meaningful, or mostly directional?
- What baseline is missing?
- Why does the main frame leave this out: “No data on observed campaigns, victim sectors, or time-to-detection metrics”?
- Why does the main frame leave this out: “No mention of whether this capability has been observed in active intrusions”?

### Who Benefits If This Frame Spreads

- **Threat intelligence analysts at The Hacker News** — Enhanced credibility as frontline observers of crimeware innovation _(Attributing new capabilities to named PhaaS platforms reinforces their role as authoritative signalers of emerging threats)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** threat normalization  
**Category:** The Fog  
**Spin Score:** 40%  

Emphasizes technical novelty and protocol abuse while minimizing evidence of actual deployment, victim impact, or defensive countermeasures; omits vendor-specific context, detection rates, or forensic artifacts.

**Who Benefits If This Frame Spreads:** Cybersecurity vendors and threat intelligence teams seeking to position themselves as early detectors of novel PhaaS capabilities.

**The Frame:** Technical threat bulletin — positioning the story as objective, timely, and authoritative reconnaissance on evolving adversary tradecraft.

### Missing Context

- No data on observed campaigns, victim sectors, or time-to-detection metrics
- No mention of whether this capability has been observed in active intrusions
- No discussion of mitigations beyond generic OAuth hygiene

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** rapidly growing cyber threat, seize control, bypass

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Article cites the capability addition but provides no screenshots, IoCs, sample logs, or third-party validation; relies on unnamed 'research' and vendor-agnostic description.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If later shown that Greatness does not yet deploy device code phishing operationally—or that the capability is nonfunctional—the attribution could undermine source credibility among technical audiences.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Greatness PhaaS now supports device code phishing to bypass MFA via OAuth 2.0.  
AI may omit the lack of empirical deployment evidence and present the capability as confirmed, widespread, and actively exploited.  
**Counter-Frame (Media):** Could be reframed as speculative reporting lacking forensic corroboration or as vendor-driven fear-mongering around OAuth design flaws.  
**Missing Voices:** OAuth standards body (IETF), identity providers (e.g., Microsoft, Google), endpoint detection vendors  

### Questions Not Answered

- What specific enterprise or consumer services were observed being targeted?
- What is the observed deployment scale or infection rate?
- Has Greatness been operationally linked to any known threat actor or infrastructure?

## Narrative Entities

- [Greatness](https://stuffthatspins.com/entities/greatness) (product — phishing-as-a-service toolkit)
- [OAuth 2.0 device authorization grant](https://stuffthatspins.com/entities/oauth-20-device-authorization-grant) (technology — abused protocol standard)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Greatness supports device code phishing to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.

**Category:** safety  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Assertion of capability addition without technical proof, telemetry, or forensic validation  
> The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing... to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.

**Evidence Gaps:** Sample device code phishing payload or redirect URI patterns; Evidence of successful MFA bypass in lab or field conditions; Independent verification from malware analysis firm or CERT  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 4, 2026  
- **SpinGraph summary:** Describes a novel attack vector using technical terminology without clarifying real-world prevalence, attribution, or mitigation efficacy — presenting it as an emergent feature rather than a verified operational capability.  
- **Likely AI summary:** Greatness PhaaS now supports device code phishing to bypass MFA via OAuth 2.0.  

## Citation Summary

This page documents the first public attribution of device code phishing functionality to the Greatness PhaaS platform, serving as a reference for threat intelligence analysts tracking crimeware evolution.

---
*HTML version: https://stuffthatspins.com/spin/greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and-steal-tokens*
