GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.
A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page. The GhostCode phishing kit does this by persuading a user to approve a device-code sign-in that is actually linked to the attacker. In one observed intrusion, the attackers made nine successful A P I calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds. The campaign began with business contact forms, used a request to sign an NDA, and delivered a password-protected HTML attachment.
This approach can defeat familiar password-theft warnings because the user sees Microsoft’s real sign-in experience. It also creates a recovery challenge because registered devices may preserve access after a stolen token is revoked. Leaders should allow device-code authentication only where a defined business process genuinely requires it. Defenders should monitor device registrations, device-code events, scripted A P I activity, and suspicious non-interactive sessions. Block device-code authentication by default, and investigate newly registered devices whenever suspicious sign-in activity appears. The wider pattern is clear: attackers increasingly focus on stealing authorization rather than stealing passwords.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.