GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds. A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page.
Daily Cyber News: GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds
A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page. The GhostCode phishing kit does this by persuading a user to approve a device-code sign-in that is actually linked to the attacker. In one observed intrusion, the attackers made nine successful A P I calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds.
Key context: This approach can defeat familiar password-theft warnings because the user sees Microsoft’s real sign-in experience.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, phishing, microsoft 365, GhostCode, hijack, Microsoft, accounts, little.
The BCM Daily Cyber News brings you clear, timely updates on threats, breaches, patches, and trends every day. Stay informed in minutes with focused audio built for busy professionals. Learn more and explore at BareMetalCyber.com.
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.
A Microsoft 365 account can be taken over even when the victim completes authentication, including multifactor authentication, on a legitimate Microsoft page. The GhostCode phishing kit does this by persuading a user to approve a device-code sign-in that is actually linked to the attacker. In one observed intrusion, the attackers made nine successful A P I calls, registered three devices in 78 seconds, and obtained a Primary Refresh Token in 32 seconds. The campaign began with business contact forms, used a request to sign an NDA, and delivered a password-protected HTML attachment.
This approach can defeat familiar password-theft warnings because the user sees Microsoft’s real sign-in experience. It also creates a recovery challenge because registered devices may preserve access after a stolen token is revoked. Leaders should allow device-code authentication only where a defined business process genuinely requires it. Defenders should monitor device registrations, device-code events, scripted A P I activity, and suspicious non-interactive sessions. Block device-code authentication by default, and investigate newly registered devices whenever suspicious sign-in activity appears. The wider pattern is clear: attackers increasingly focus on stealing authorization rather than stealing passwords.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.