Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
Key Takeaways Attackers successfully bypassed Microsoft 365’s multi-factor authentication (MFA) to hijack a finance employee’s mailbox. The incident utilized an adversary-in-the-middle...
Key Takeaways
- Attackers successfully bypassed Microsoft 365’s multi-factor authentication (MFA) to hijack a finance employee’s mailbox.
- The incident utilized an adversary-in-the-middle (AiTM) phishing technique, capturing an authenticated session cookie without deploying malware.
- The compromise led to a sophisticated, two-phase business email compromise (BEC) campaign, diverting vendor payments over 30 days.
- The attack highlights a critical vulnerability where MFA alone cannot fully protect against session hijacking via real-time login relays.
Attackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox
A recent, sophisticated phishing attack successfully circumvented Microsoft 365’s multi-factor authentication (MFA) to gain control of a finance employee’s email account, ultimately leading to the redirection of vendor payments. This incident, detailed by TrendAI, underscores a critical vulnerability in identity-focused security, demonstrating how attackers can bypass robust authentication mechanisms without resorting to malware deployment or direct device compromise.
Table Of Content
The infiltration began with a highly targeted spear-phishing email. Disguised as an HR notification regarding a denied paid-time-off (PTO) request, the message was personalized with the recipient’s name, role, and organizational details, lending it significant credibility. The email prompted the finance employee to review “conflicting dates” via a link. This link, however, initiated a series of redirects, ultimately leading the victim to a meticulously crafted, fraudulent Microsoft 365 sign-in page.
The Adversary-in-the-Middle (AiTM) Technique
Analysts from TrendAI said in a report shared that the fake login page operated as an adversary-in-the-middle (AiTM) relay. This advanced phishing technique intercepted the user’s login credentials and real-time MFA approval, forwarding them to the legitimate Microsoft 365 service. Crucially, upon successful authentication, the AiTM server captured the valid session cookie generated by Microsoft 365. This session cookie, rather than repeated password or MFA prompts, became the attackers’ key to persistent access.
With the stolen session cookie, the attackers could replay the authenticated session from various commercial VPN infrastructures, appearing to Microsoft 365 as the legitimate, already logged-in employee. This method bypasses the need for further MFA challenges or password re-entry. TrendAI’s investigation revealed suspicious sign-ins from geographically disparate locations, specifically Amsterdam and Los Angeles, occurring within approximately one minute of each other—an impossible travel pattern indicative of compromise. Microsoft 365 telemetry confirmed that MFA was marked as satisfied, with no new challenges, failed login attempts, or conditional access controls triggered for these replayed sessions.
Once inside, the attackers leveraged the compromised user’s existing permissions to access Exchange Online, SharePoint, Microsoft 365 Search, and a shared accounts-payable mailbox. This deep access provided them with authentic invoices, payment discussions, and vendor details, enabling them to craft highly convincing fraudulent payment requests.
Fraud Hidden Inside Mailboxes
The payment diversion scheme was meticulously executed in two distinct phases over roughly 30 days, demonstrating significant planning and persistence.
Phase 1: Vendor Impersonation
In the initial phase, attackers impersonated a vendor’s accounts-payable contact using a free webmail account. They referenced approximately 20 legitimate outstanding invoices, requesting a switch from paper checks to ACH payments. To bolster their credibility, they supplied fraudulent authorization and tax documents. The attackers maintained active communication for over three weeks, applying steady pressure on the finance team to update the vendor’s banking details. Critically, their access to the compromised mailbox provided real-time visibility into internal conversations and payment statuses, allowing them to adapt their strategy and ensure their fraudulent requests appeared routine.
Phase 2: Internal Impersonation and Concealment
The second phase involved impersonating a senior accounts-payable colleague using a look-alike domain. Through internal-looking verification messages, they pushed several vendor banking updates through the company’s approval processes. This combination of external vendor impersonation and internal employee impersonation created an illusion of independent confirmation, significantly increasing the likelihood of the fraudulent changes being approved. This tactic closely mirrors known business email compromise (BEC) payment diversion attack chains, where criminals monitor legitimate business discussions before inserting fraudulent bank details.
To evade detection, the threat actors implemented three malicious inbox rules within the compromised mailbox. These rules automatically archived and marked vendor collection notices as read, and crucially, prevented any subsequent rules from processing these messages. They also deleted emails that could expose the scam, ensuring that legitimate overdue payment notices from the real vendor remained unseen by the finance team.
For more technical details on the indicators of compromise, refer to the full report on the Microsoft 365 MFA bypass and mailbox hijack.
What You Should Do
- Monitor for Impossible Travel and Anomalous Activity: Implement and actively monitor for impossible travel alerts, alongside suspicious mailbox rule changes, unusual token activity, and email deletions.
- Enable Token Protection: Where available, enable token protection features to prevent the replay of stolen session cookies.
- Revoke Active Sessions: Immediately revoke all active sessions for any user account suspected of compromise.
- Strengthen Payment Verification Processes: Mandate dual approval for all vendor payment instruction changes. Crucially, require an out-of-band phone verification using a trusted, pre-registered number for such changes.
- Deploy Phishing-Resistant MFA: Adopt phishing-resistant authentication methods (e.g., FIDO2 security keys) to significantly reduce exposure to AiTM and other MFA bypass phishing techniques.
- User Training: Regularly train employees on the evolving tactics of spear-phishing and AiTM attacks, emphasizing the dangers of clicking suspicious links and entering credentials on unfamiliar pages.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.