Bottom line: Microsoft 365 users are vulnerable to exploitation via the GhostCode phishing kit due to a legitimate device authorization flow weakness.
What's happening: Researchers in eSentire’s threat response unit identified the GhostCode campaign in late August 2026. The campaign targets users in the United States, Canada, and the United Kingdom, with attackers using legitimate Microsoft 365 device authorization flow indicators to trick victims into granting unauthorized access to their accounts.
What to do: Security leaders should immediately block access to any Microsoft 365 device authorization flow indicators, and implement additional security measures to prevent similar phishing attacks.