Cybercriminals have always embraced new technologies to improve their effectiveness. Today, artificial intelligence has become another tool that can help threat actors operate faster and at greater scale.
What once required extensive technical expertise and manual effort can increasingly be automated. AI can help attackers identify high-value targets, generate convincing social engineering content, adapt campaigns in real time, and accelerate post-compromise activities. The result is the potential for more personalized and scalable attacks that can be harder to detect.
Proofpoint’s recent research into device code phishing offers an example of this evolution. While device code phishing exploits legitimate cloud authentication workflows, AI can help attackers make these campaigns more convincing and effective. Together, these techniques illustrate a shift beyond traditional credential theft toward identity-centric attacks designed to exploit trust.
The rise of AI-enhanced device code phishing
Device code phishing shows how attackers can combine legitimate cloud authentication workflows with AI-powered social engineering .
Unlike traditional phishing attacks that rely on fake login pages to steal passwords, device code phishing abuses a legitimate authentication mechanism used by Microsoft and other cloud providers. Victims are persuaded to enter a valid device code into a legitimate authentication portal, unknowingly granting attackers access tokens without giving up their passwords directly.
Because the victim is interacting with a legitimate authentication page, traditional phishing indicators may be absent. That can make the attack harder for users and some security controls to recognize.
The emergence of EvilTokens, a phishing-as-a-service (PhaaS) platform built around device code phishing, illustrates how the technique can be packaged for broader use. Rather than requiring significant expertise to execute these campaigns, platforms such as EvilTokens package sophisticated attack workflows into scalable services that a wider range of threat actors can use.
AI can also amplify several stages of the attack lifecycle.

Figure 1: Device code phishing works because step 3 happens on Microsoft's own real sign-in page — there's no fake site for anyone to spot.
AI-powered reconnaissance and target selection
Before launching an attack, threat actors can use AI tools to rapidly analyze publicly available information about organizations, employees, suppliers, and business relationships.
This intelligence can help them identify users with privileged access, executives involved in sensitive initiatives, or employees who may be more likely to respond to authentication requests. Rather than sending generic phishing emails to thousands of recipients, attackers can focus their efforts on a smaller number of high-value targets.
AI can also help attackers refine targeting criteria, prioritize potential victims, and identify business context that could make a device code phishing request appear legitimate.
More convincing social engineering
Device code phishing succeeds when attackers persuade users to complete an authentication flow that appears legitimate.
Generative AI can help threat actors create personalized phishing messages tailored to a target’s role, projects, colleagues, vendors, and business activities. These communications can imitate requests from IT administrators, collaboration platform support teams, trusted suppliers, or internal stakeholders.
AI-generated content can also reduce grammatical errors, awkward phrasing, and other inconsistencies that people have traditionally associated with phishing attempts. It can help attackers overcome language barriers and tailor messages for different audiences. As a result, malicious authentication requests can appear more polished and credible.
Platforms such as EvilTokens demonstrate how these capabilities can be operationalized at scale. By leveraging AI, attackers can rapidly generate customized phishing lures for different organizations, departments, and user populations while maintaining consistency and quality across large-scale campaigns.
Multichannel attack delivery
Modern attacks do not always begin and end in email.
AI can help attackers rapidly generate and customize content across multiple communication channels, including email, Microsoft Teams, Slack, SMS, social media, and voice communications.
A phishing campaign, for example, could begin with an email, continue through a collaboration platform, and conclude with a phone call from someone impersonating an IT administrator. Consistent messaging across several trusted channels can make an attack appear more legitimate.
This multichannel approach reflects a broader challenge: attackers can reach users across the tools and services they use to work.
Real-time engagement and adaptation
AI can also enable attackers to engage targets more dynamically.
Instead of relying only on static phishing templates, threat actors can use generative AI to produce responses in real time, answer questions, and maintain convincing conversations during an attack.
The result can feel less like a traditional phishing attempt and more like an interaction with a help desk technician, software provider, or trusted colleague.
Accelerated post-compromise activity
The danger does not end when an attacker gains access.
After obtaining access tokens through device code phishing, attackers may use AI tools to help analyze mailbox contents, organizational relationships, collaboration data, and cloud applications to identify valuable assets and additional targets.
Compromised accounts can then be used to launch internal phishing campaigns, supplier fraud schemes, business email compromise (BEC) attacks, and other identity-based threats. Automation and AI can potentially shorten the time between initial access and subsequent attacker activity.
AI is expanding threats beyond email
Device code phishing is only one example of a broader trend. Across the threat landscape, AI can help adversaries enhance multiple stages of the cyberattack lifecycle.
Attackers can use AI to:
- Identify high-value targets through automated reconnaissance
- Generate personalized phishing and impersonation content
- Scale content across email, collaboration platforms, and social channels
- Create more convincing business email compromise content
- Automate interactions with potential victims
- Analyze compromised environments
- Support fraud, impersonation, and supplier compromise campaigns
At the same time, organizations are increasingly adopting AI assistants, cloud applications, collaboration platforms, and other digital tools that expand the environments security teams must protect. As trusted communications spread across email, messaging platforms, cloud applications, and supplier ecosystems, attackers have more opportunities to exploit legitimate workflows and trusted identities.
The challenge is no longer simply stopping malicious emails. Organizations need to identify, correlate, and respond to threats wherever people work.
Why disconnected security tools create gaps
As attackers target identities, cloud services, collaboration platforms, and trusted business communications, organizations may rely on multiple security tools that do not share enough context.
Fragmented security architectures can create visibility gaps. An authentication event may appear normal in one system while suspicious behavior appears in another. Without correlation across environments, security teams can miss the broader attack sequence.
Defending against AI-enabled attacks requires visibility across the attack chain—from initial social engineering and authentication abuse to account takeover, lateral movement, and post-compromise activity.
Organizations need the ability to:
- Protect users across multiple communication channels
- Correlate signals from identities, email, cloud applications, and collaboration tools
- Detect attacks across multiple stages of the threat lifecycle
- Accelerate investigation and remediation
- Reduce operational complexity through automation
Defending against AI-powered threats with Proofpoint Collaboration Security Prime
As attackers increasingly use AI in multichannel and multistage attacks, organizations need more than disconnected security tools. They need an integrated approach that can protect people wherever they work, correlate signals across the attack lifecycle, and accelerate response.
Proofpoint Collaboration Security Prime helps organizations defend against AI-scaled threats by delivering integrated protection across email, collaboration platforms, cloud applications, identities, and trusted business communications. By combining coverage across security control points, correlated threat intelligence, automated detection and remediation, and AI-powered threat protection in a centralized platform, Proofpoint Collaboration Security Prime helps security teams identify sophisticated attacks such as device code phishing, respond effectively, and reduce operational complexity.
It also helps strengthen human resilience through risk-based guidance and education, helping organizations prepare for evolving AI-enabled threats.
To learn more about how Proofpoint Collaboration Security Prime can help your organization prepare for AI-scaled attacks, visit the Proofpoint Collaboration Security Prime page.