[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2VX_VkCudpfuy3mKiLInW_o8KKSE16Nd8dCc0hka1cM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"ffe0cbe1-0e78-4dcc-a49c-b4fc5368acf1","aitm-phishing-bypasses-mfa-to-hijack-microsoft-365-finance-accounts","7d9e3af5-9b14-4fcc-a0ea-b0be1f278010","AitM Phishing Bypasses MFA to Hijack Microsoft 365 Finance Accounts","Adversary-in-the-middle (AitM) phishing attacks intercept authentication sessions in real time, allowing attackers to steal session tokens even when multi-factor authentication is enabled — rendering traditional MFA alone insufficient. By targeting employees in payroll and finance workflows, attackers maximise the potential for fraud and sensitive data exfiltration. The use of residential proxies and legitimate redirect services makes these attacks exceptionally difficult to detect with standard email and sign-in filters. This campaign highlights that credential-based defences must be layered with session-aware controls and continuous behavioural monitoring to be effective.","**Immediate actions:**\n- Deploy phishing-resistant MFA (FIDO2\u002Fpasskeys) to replace SMS or app-based OTP, which AitM attacks can bypass.\n- Enable Microsoft 365 Conditional Access policies to block sign-ins from anonymising proxies and unexpected geolocations.\n- Brief finance and payroll staff immediately on AitM phishing tactics and how to verify suspicious login prompts.\n\n**Long-term improvements:**\n- Implement Continuous Access Evaluation (CAE) and token-binding controls to invalidate stolen session tokens in real time.\n- Enforce strict email authentication (DMARC, DKIM, SPF) and deploy anti-phishing policies that flag multi-stage redirect chains.\n- Establish a privileged access model that limits which accounts can access sensitive financial mailboxes and workflows.\n\n**Detection measures:**\n- Monitor Microsoft 365 sign-in logs for anomalous indicators such as residential proxy IP ranges, impossible travel, and token replay events.\n- Configure SIEM alerts for concurrent sessions from different locations or devices on the same account within short time windows.\n- Regularly audit conditional access policy coverage to ensure no accounts or applications are exempt from enforcement.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","CIS Control 9 – Email and Web Browser Protections","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-63B – Digital Identity Guidelines (Phishing-Resistant AAL3)","NIST AC-2 – Account Management","NIST AC-17 – Remote Access","NIST SI-3 – Malicious Code Protection","NIST DE.CM-1 – Network Monitoring","MITRE ATT&CK T1557 – Adversary-in-the-Middle","MITRE ATT&CK T1539 – Steal Web Session Cookie","GDPR Article 32 – Security of Processing","ISO\u002FIEC 27001 A.9.4 – System and Application Access Control","published","2026-08-07T12:20:36.873278+00:00","2026-08-07T12:20:36.597+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fmicrosoft-365-aitm-phishing-hijacks.html","microsoft-365-aitm-phishing-hijacks-accounts-to-collect-payroll-and-finance-emai-e7fa1f","Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]