Ghost Phishing: The Email Attack Las Vegas Businesses Can’t See Coming
A new business email compromise technique hides inside an encrypted browser page — and it is already bypassing the spam filters Las Vegas companies rely on.
Published by CMIT Solutions of Las Vegas · Cybersecurity · 6 min read
What Is “Ghost Phishing,” and Why Does It Matter to Las Vegas Businesses?
Security researchers are tracking a new wave of business email compromise attacks built around a technique nicknamed “ghost phishing.” The campaign, identified by threat intelligence firm ANY.RUN and reported by The Hacker News in July 2026, uses a malware kit called EvilTokens to hijack Microsoft 365 accounts without ever stealing a password directly.
Here is what makes it dangerous for small and mid-sized Las Vegas businesses specifically: the malicious page does not exist until it is already inside your employee’s browser. The email itself passes standard link and attachment scans because the phishing content is encrypted. It only decrypts and renders after the browser opens it — which means the security tools most local businesses depend on, from basic spam filters to network-level URL checks, never see the actual attack.
Threat intelligence firm ANY.RUN analyzed sandbox submissions from 15,000 organizations and found phishing exposure reaching 75.6% in consulting firms, 72.8% in financial services, 71.9% in manufacturing, 67.9% in technology, and 66.1% among managed security providers — sectors with a heavy presence in the Las Vegas and Henderson business community.
How the Attack Actually Works
Ghost phishing does not rely on a fake login page that looks slightly off. It uses Microsoft Device Code Phishing, a legitimate Microsoft sign-in flow normally used to log in to smart TVs, printers, and other devices without a keyboard. Attackers trick an employee into entering a real, attacker-generated device code on a real Microsoft login screen — and the employee unknowingly authorizes the attacker’s session themselves.
- The lure: An email disguised as a meeting invite, document share, or vendor notification directs the employee to a link.
- The hidden payload: The destination page’s HTML is encrypted with AES-GCM encryption, so it looks blank or harmless to automated scanners and email security gateways.
- The render: Once opened in a real browser, the page decrypts and displays a legitimate-looking Microsoft device code prompt.
- The handoff: The employee enters the code, unintentionally granting the attacker a valid, authenticated session — no stolen password required.
- The payoff: The attacker now has standing access to email, files, and connected cloud apps until someone notices and revokes the session.
Because no password is stolen and no malicious file is downloaded, this attack slides past the two things most Las Vegas small businesses check for. That is exactly why the FBI’s Internet Crime Complaint Center (IC3) reported $3.046 billion in business email compromise losses in 2025 alone — making BEC the single most financially destructive attack category aimed at businesses in the country.
This is also why annual phishing-awareness training, on its own, is no longer enough. Most employee training still centers on spotting a fake domain or a misspelled sender name. Ghost phishing sails past both, because the page an employee sees really is served from Microsoft’s own infrastructure right up until the moment it decrypts. Las Vegas businesses that treat security awareness as a once-a-year checkbox rather than one layer among several are the ones most exposed to this technique.
What’s at Stake for Las Vegas Businesses
Clark County’s economy runs on a dense web of vendors, contractors, and service providers who all trust each other’s email. A single compromised Microsoft 365 account does not stay contained to one company — it becomes a launching pad for fraudulent invoices, redirected payments, and follow-on attacks against every partner in that inbox’s contact list. That makes the following Las Vegas sectors especially exposed right now:
- ⚠Professional services and law firms handling client trust funds, contracts, and confidential case data through Microsoft 365
- ⚠Financial services firms and credit unions where a compromised inbox can trigger fraudulent wire transfer requests
- ⚠Henderson-area manufacturers and industrial suppliers connected to hospitality and gaming supply chains
- ⚠Hospitality and gaming vendors whose compromised accounts can be used to pivot into partner networks
- ⚠Any business that relies on Microsoft 365 without phishing-resistant multi-factor authentication in place
Closing the Gaps: Three Fixes Every Las Vegas Business Needs
• Employees Trust the Login Screen Because It’s Real
The GapStaff are trained to spot spoofed URLs and lookalike domains. Ghost phishing uses Microsoft’s own legitimate login flow, so there is no fake domain to catch.
The FixDeploy phishing-resistant MFA, such as FIDO2 security keys or passkeys bound to a physical device. A device code alone should never be sufficient to complete authentication for sensitive accounts.
• Email Security Stops Checking After Delivery
The GapSecure email gateways and URL scanners inspect a link once, at delivery. Encrypted, browser-rendered payloads are invisible at that stage.
The FixLayer in endpoint detection and response (EDR) and conditional access monitoring that watches for anomalous OAuth consent grants and device code redemptions, not just what arrives in the inbox.
• No One Notices Until the Damage Is Done
The GapOnce a device code is authorized, the attacker’s session looks like a normal employee login. Without active monitoring, it can go unnoticed for days or weeks.
The FixPut 24/7 monitoring in place that flags impossible travel, new-device logins, and off-hours access, with the ability to revoke a session immediately — not the next business day.
Las Vegas Businesses: Don’t Wait for the Breach.
Find out whether your Microsoft 365 environment is protected against device code phishing before an attacker does.
Defending Las Vegas with CMIT Solutions
Business email compromise techniques like ghost phishing evolve faster than most in-house IT teams can track alone. CMIT Solutions of Las Vegas monitors emerging threats like the EvilTokens campaign and builds layered defenses — phishing-resistant MFA, conditional access policies, and 24/7 monitoring — specifically for the Clark County businesses that gaming, hospitality, healthcare, legal, and manufacturing clients depend on every day.
The Hacker News — “New Ghost Phishing Wave Is Breaking Traditional Email Security” (July 8, 2026)
Nacha — “FBI’s IC3 Finds Almost $8.5 Billion Lost to Business Email Compromise in Last Three Years” (2026 IC3 report coverage)
Protect Your Las Vegas Business Today
Don’t let a decrypted browser page become your next business email compromise incident.
Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com