09/01/2026
"Never approve a sign-in you didn't start."
Here's a phishing tactic that never touches your password — and slips past most email security scanning.
Researchers are calling it "ghost phishing." The malicious content stays encrypted until it renders inside the victim's browser, so scanners see nothing suspicious. It gets paired with Microsoft's device-code sign-in flow: the user is prompted to approve a sign-in or enter a code, they do it, and the attacker has the account. No password ever gets stolen.
When the security tooling can't see it, the person is the control.
**The habit that stops it cold:** never approve a sign-in request or enter a device code you didn't personally initiate. If a prompt appears and you didn't start it, don't proceed — report it.
One sentence, in a team meeting, closes this entire attack path.
` `
https://paconnect.com/