< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

started · updated

Microsoft 365 session theft campaign bypasses MFA to redirect payments

Cybersecurity firm TrendAI has uncovered a sophisticated business email compromise (BEC) campaign that successfully bypassed multi-factor authentication (MFA) to hijack Microsoft 365 sessions and redirect vendor payments.

The attack utilized highly personalized spear-phishing emails themed around denied paid-time-off (PTO) requests. These emails included the target's name, job title, and organization details to increase credibility. When victims clicked the provided links, they were directed through a series of redirects to a counterfeit Microsoft 365 sign-in page. This page functioned as an adversary-in-the-middle (AiTM) relay, allowing attackers to capture live authenticated session tokens rather than just passwords.

Once access was gained, the attackers implemented three malicious inbox rules to auto-archive and mark incoming vendor and internal collection emails as read. This tactic allowed the attackers to conceal their activities for approximately 30 days. During this period, they impersonated vendors and rerouted company payments to bank accounts under their control. The incident highlights a growing vulnerability in identity-focused security, where attackers target authenticated browser sessions to circumvent traditional MFA protections.

Entities

Microsoft · SendGrid · TrendAI