Skip to content

Microsoft 365 Phishing Campaign Hijacks Accounts to Spy on Finance and Payroll Departments

Bottom line: An AitM phishing campaign hijacks Microsoft 365 accounts via residential proxies to specifically identify finance and payroll employees and harvest their email communications.

Security researchers are warning of a broad, email-based phishing campaign that uses Adversary-in-the-Middle (AitM) techniques to take over Microsoft 365 accounts. The goal is to identify employees involved in financial processes and systematically collect associated email correspondence.

The identified campaign uses AitM phishing to intercept credentials and session cookies of Microsoft 365 users in real time. This allows attackers to bypass classic multi-factor authentication, as they hijack the complete session after a successful login rather than merely stealing passwords. After taking over an account, the attackers specifically search mailboxes for individuals involved in payroll and finance workflows and collect the corresponding email communication.

A key feature of the campaign is the use of residential proxies to disguise malicious login attempts as ordinary consumer traffic. This complicates IP-based anomaly detection and geographic access controls, since the logins appear to originate from regular residential IP ranges instead of known data centers or VPN exit nodes, which classic detection rules typically flag.

For CISOs, it is relevant that this campaign specifically targets finance and payroll personnel, with the obvious follow-up objective of business email compromise (BEC) and fraudulent wire transfers or payroll redirection. The combination of AitM techniques and residential proxies undermines many standard detection mechanisms that rely on unusual IP addresses or impossible travel times.

Recommended countermeasures include deploying phishing-resistant authentication such as FIDO2/WebAuthn, which is inherently more robust against AitM attacks than classic MFA methods. In addition, conditional access policies should be tightened, session token lifetimes shortened, and monitoring expanded to cover unusual mailbox rules as well as access to finance- and HR-related emails. Targeted awareness training for employees in finance and payroll functions regarding this specific attack method is advised.


Source: thehackernews.com · Published August 7, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: