Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake CAPTCHA Installs Malware That Kills 145 Security Processes
August 20, 2026
New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
August 20, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
August 20, 2026
Home/Threats/Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
Threats

Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes

Key Takeaways Attackers successfully bypassed Microsoft 365’s multi-factor authentication (MFA) to hijack a finance employee’s mailbox. The incident utilized an adversary-in-the-middle...

Sarah simpson
Sarah simpson
August 20, 2026 4 Min Read
3 0

Key Takeaways

  • Attackers successfully bypassed Microsoft 365’s multi-factor authentication (MFA) to hijack a finance employee’s mailbox.
  • The incident utilized an adversary-in-the-middle (AiTM) phishing technique, capturing an authenticated session cookie without deploying malware.
  • The compromise led to a sophisticated, two-phase business email compromise (BEC) campaign, diverting vendor payments over 30 days.
  • The attack highlights a critical vulnerability where MFA alone cannot fully protect against session hijacking via real-time login relays.

Attackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox

A recent, sophisticated phishing attack successfully circumvented Microsoft 365’s multi-factor authentication (MFA) to gain control of a finance employee’s email account, ultimately leading to the redirection of vendor payments. This incident, detailed by TrendAI, underscores a critical vulnerability in identity-focused security, demonstrating how attackers can bypass robust authentication mechanisms without resorting to malware deployment or direct device compromise.

Table Of Content

  • Key Takeaways
  • Attackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox
  • The Adversary-in-the-Middle (AiTM) Technique
  • Fraud Hidden Inside Mailboxes
  • Phase 1: Vendor Impersonation
  • Phase 2: Internal Impersonation and Concealment
  • What You Should Do

The infiltration began with a highly targeted spear-phishing email. Disguised as an HR notification regarding a denied paid-time-off (PTO) request, the message was personalized with the recipient’s name, role, and organizational details, lending it significant credibility. The email prompted the finance employee to review “conflicting dates” via a link. This link, however, initiated a series of redirects, ultimately leading the victim to a meticulously crafted, fraudulent Microsoft 365 sign-in page.

The Adversary-in-the-Middle (AiTM) Technique

Analysts from TrendAI said in a report shared that the fake login page operated as an adversary-in-the-middle (AiTM) relay. This advanced phishing technique intercepted the user’s login credentials and real-time MFA approval, forwarding them to the legitimate Microsoft 365 service. Crucially, upon successful authentication, the AiTM server captured the valid session cookie generated by Microsoft 365. This session cookie, rather than repeated password or MFA prompts, became the attackers’ key to persistent access.

With the stolen session cookie, the attackers could replay the authenticated session from various commercial VPN infrastructures, appearing to Microsoft 365 as the legitimate, already logged-in employee. This method bypasses the need for further MFA challenges or password re-entry. TrendAI’s investigation revealed suspicious sign-ins from geographically disparate locations, specifically Amsterdam and Los Angeles, occurring within approximately one minute of each other—an impossible travel pattern indicative of compromise. Microsoft 365 telemetry confirmed that MFA was marked as satisfied, with no new challenges, failed login attempts, or conditional access controls triggered for these replayed sessions.

Once inside, the attackers leveraged the compromised user’s existing permissions to access Exchange Online, SharePoint, Microsoft 365 Search, and a shared accounts-payable mailbox. This deep access provided them with authentic invoices, payment discussions, and vendor details, enabling them to craft highly convincing fraudulent payment requests.

Fraud Hidden Inside Mailboxes

The payment diversion scheme was meticulously executed in two distinct phases over roughly 30 days, demonstrating significant planning and persistence.

Phase 1: Vendor Impersonation

In the initial phase, attackers impersonated a vendor’s accounts-payable contact using a free webmail account. They referenced approximately 20 legitimate outstanding invoices, requesting a switch from paper checks to ACH payments. To bolster their credibility, they supplied fraudulent authorization and tax documents. The attackers maintained active communication for over three weeks, applying steady pressure on the finance team to update the vendor’s banking details. Critically, their access to the compromised mailbox provided real-time visibility into internal conversations and payment statuses, allowing them to adapt their strategy and ensure their fraudulent requests appeared routine.

Phase 2: Internal Impersonation and Concealment

The second phase involved impersonating a senior accounts-payable colleague using a look-alike domain. Through internal-looking verification messages, they pushed several vendor banking updates through the company’s approval processes. This combination of external vendor impersonation and internal employee impersonation created an illusion of independent confirmation, significantly increasing the likelihood of the fraudulent changes being approved. This tactic closely mirrors known business email compromise (BEC) payment diversion attack chains, where criminals monitor legitimate business discussions before inserting fraudulent bank details.

To evade detection, the threat actors implemented three malicious inbox rules within the compromised mailbox. These rules automatically archived and marked vendor collection notices as read, and crucially, prevented any subsequent rules from processing these messages. They also deleted emails that could expose the scam, ensuring that legitimate overdue payment notices from the real vendor remained unseen by the finance team.

For more technical details on the indicators of compromise, refer to the full report on the Microsoft 365 MFA bypass and mailbox hijack.

What You Should Do

  • Monitor for Impossible Travel and Anomalous Activity: Implement and actively monitor for impossible travel alerts, alongside suspicious mailbox rule changes, unusual token activity, and email deletions.
  • Enable Token Protection: Where available, enable token protection features to prevent the replay of stolen session cookies.
  • Revoke Active Sessions: Immediately revoke all active sessions for any user account suspected of compromise.
  • Strengthen Payment Verification Processes: Mandate dual approval for all vendor payment instruction changes. Crucially, require an out-of-band phone verification using a trusted, pre-registered number for such changes.
  • Deploy Phishing-Resistant MFA: Adopt phishing-resistant authentication methods (e.g., FIDO2 security keys) to significantly reduce exposure to AiTM and other MFA bypass phishing techniques.
  • User Training: Regularly train employees on the evolving tactics of spear-phishing and AiTM attacks, emphasizing the dangers of clicking suspicious links and entering credentials on unfamiliar pages.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Zyxel Patches Critical Command Injection Vulnerability in 18 Access Point Models

Next Post

New Android Malware Steals Banking PINs and Relays Data Through Infected Phones

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Red Hat OpenShift CVE-2023-39418 Exposes Internal Services
August 20, 2026
OpenAI Pauses AI Model Training Over 0-Day Discovery Concerns
August 20, 2026
Cisco AnyConnect VPN Client Critical RCE Vulnerability CVE-2020-3556 Patched
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us