Microsoft Security Blog · April 6, 2026

Inside an AI‑enabled device code phishing campaign

Why it matters

A device code phishing campaign uses AI and end-to-end automation to scale account compromise and sustain post-compromise access.

My takeaway: Directly relevant to AI abuse: generative content and automation are improving the conversion rate and scale of phishing operations. Defensive teams need to model how AI compresses attacker iteration loops.