Awareness Lessons
2 months ago
AitM Phishing Bypasses MFA to Hijack Microsoft 365 Finance Accounts
Adversary-in-the-middle (AitM) phishing attacks intercept authentication sessions in real time, allowing attackers to steal session tokens even when multi-factor authentication is enabled — rendering traditional MFA alone insufficient. By targeting employees in payroll and finance workflows, attackers maximise the potential for fraud and sensitive data exfiltration. The use of residential proxies and legitimate redirect services makes these attacks exceptionally difficult to detect with standard email and sign-in filters. This campaign highlights that credential-based defences must be layered with session-aware controls and continuous behavioural monitoring to be effective.
Tactical Insight
Immediate actions
- Deploy phishing-resistant MFA (FIDO2/passkeys) to replace SMS or app-based OTP, which AitM attacks can bypass.
- Enable Microsoft 365 Conditional Access policies to block sign-ins from anonymising proxies and unexpected geolocations.
- Brief finance and payroll staff immediately on AitM phishing tactics and how to verify suspicious login prompts.
Long-term improvements
- Implement Continuous Access Evaluation (CAE) and token-binding controls to invalidate stolen session tokens in real time.
- Enforce strict email authentication (DMARC, DKIM, SPF) and deploy anti-phishing policies that flag multi-stage redirect chains.
- Establish a privileged access model that limits which accounts can access sensitive financial mailboxes and workflows.
Detection measures
- Monitor Microsoft 365 sign-in logs for anomalous indicators such as residential proxy IP ranges, impossible travel, and token replay events.
- Configure SIEM alerts for concurrent sessions from different locations or devices on the same account within short time windows.
- Regularly audit conditional access policy coverage to ensure no accounts or applications are exempt from enforcement.