Proofpoint published analysis in May 2026 on device code phishing attacks, noting that codes are now generated dynamically when users click phishing links. They highlighted the availability of PhaaS offerings like EvilTokens and Tycoon for these attacks.