Published Security3 min read
The 15x Number: Device Code Phishing and Vishing Are Where 2026 Actually Moved
CrowdStrike's headline figures for the first half of 2026 describe growth in techniques that never touch a vulnerability. Picus Labs' simulation data explains why that pays: the interior stops barely one attack in three.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- The CrowdStrike 2026 Threat Hunting Report states that monthly device code phishing attempts jumped 15x in the past six months.
- CrowdStrike reports vishing intrusions in the first half of 2026 increased 2x compared to the second half of 2025.
- CrowdStrike reports that eCrime actors CORDIAL SPIDER and SNARKY SPIDER used vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts, and that in one case SNARKY SPIDER moved from account takeover to data theft in under five minutes.
- From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public proof of concept was conducted within 48 hours of the PoC's release.
- Picus Labs' Blue Report 2026 measured more than 338 million real attack simulations across actual client production environments in the first half of 2026.
Compiled by The WatchSomething wrong?How this is made
Why it matters
CrowdStrike's 2026 Threat Hunting Report puts two numbers on the part of the attack surface that grew fastest: monthly device code phishing attempts up 15x over the past six months, and vishing intrusions in the first half of 2026 running at twice the level of the second half of 2025 [1][2]. Both routes arrive through an identity flow or a person answering a phone, which matters because the defensive telemetry from the same period shows that controls have improved at the perimeter and not behind it [10][11].
Take the growth rates at face value and device code phishing expanded at roughly seven and a half times the pace of vishing over comparable half-year windows [1]. That is the more interesting of the two, because it is the one with no human in the loop on the defender's side to be trained, coached, or scripted.
The vishing cases are the ones with named actors attached. CrowdStrike reports that CORDIAL SPIDER and SNARKY SPIDER used voice calls to pull data out of SaaS applications and to compromise single sign-on accounts, and that in one incident SNARKY SPIDER went from account takeover to data theft in under five minutes [3]. For comparison, the same report found 88% of observed exploitation of vulnerabilities with a public proof of concept happened within 48 hours of that PoC being published [7]. The identity path does not need 48 hours. It needs one call.
What makes the arithmetic uncomfortable is the other half of the picture. Picus Labs' Blue Report 2026, drawn from more than 338 million attack simulations in its clients' production environments in the first half of 2026, found average prevention effectiveness up from 62% to 69% and logging at a four-year high of 58% [9][10]. Its first measurement of post-compromise prevention, testing what breaks the chain once an adversary is operating inside as an authenticated user, came in at 37% [11]. That is a 32 point gap between the outside and the inside [2], and an attacker who authenticates through a device code flow or a reset help desk ticket starts on the wrong side of it.
Inside, the failures are not evenly distributed. Noisy actions get stopped: lateral movement via service execution around 90%, UAC bypass around 85% [14]. Quiet work does not: reconnaissance such as domain mapping and share and session enumeration was prevented 10% of the time, credential reads from memory around 22%, and one registry-based variant in under 1% of attempts [12][13]. The single least-prevented technique in the dataset was hiding command history, stopped 1% of the time [15].
Two caveats belong in the same paragraph as the headline. CrowdStrike published multiples, not counts, so a 15x rise has no denominator attached [16]. Picus measured its own client base, using simulations rather than live intrusions [9]. Neither vendor is disinterested in the conclusion that identity and post-compromise coverage need buying.
Worth watching: whether the device code phishing multiple holds when the second half of 2026 is counted, or whether it flattens the way most first-year growth curves do. Whether identity provider and help desk ticket logs are inside the 58% logging figure or outside it [10]. And whether the 37% post-compromise rate moves at all next year, given that the perimeter took two years to recover seven points [10][11][3].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The CrowdStrike 2026 Threat Hunting Report states that monthly device code phishing attempts jumped 15x in the past six months.
- [2]
CrowdStrike reports vishing intrusions in the first half of 2026 increased 2x compared to the second half of 2025.
- [3]
CrowdStrike reports that eCrime actors CORDIAL SPIDER and SNARKY SPIDER used vishing to exfiltrate data from SaaS applications and compromise single sign-on accounts, and that in one case SNARKY SPIDER moved from account takeover to data theft in under five minutes.
- [7]
From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public proof of concept was conducted within 48 hours of the PoC's release.
- [9]
Picus Labs' Blue Report 2026 measured more than 338 million real attack simulations across actual client production environments in the first half of 2026.
- [10]
In the Blue Report 2026, average prevention effectiveness climbed from 62% to 69%, matching its 2024 peak, and logging reached a four-year high of 58%.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- crowdstrike.comCounter Adversary OperationsCrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
Additional citations
- CrowdStrike 2026 Threat Hunting Report
- Picus Labs Blue Report 2026, via The Hacker News
- CrowdStrike 2026 Threat Hunting Report blog post



