AI Weekly Malaysia

Back to items Summaries

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

ID
11901
Status
summarized
Published
07 Aug 2026, 6:38 PM
Fetched
07 Aug 2026, 7:47 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
07 Aug 2026, 7:49 PM
Tags
Audience
developerssaas_founders

What happened

Arctic Wolf Labs reports a widespread AitM phishing campaign hijacking Microsoft 365 accounts via voicemail-themed emails, using a six-stage redirect chain through Google Meet, Google Ads, and Amazon S3 to bypass reputation filters. Compromised sessions are maintained at roughly eight-hour intervals using residential proxies, and attackers target employees in financial workflows to reroute payroll payments. Hundreds of organizations were hit last month across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe.

Why it matters

If your organization runs on Microsoft 365, MFA alone does not stop this attack—AitM proxies capture credentials and MFA codes in real time. Founders and IT leads should verify whether conditional access policies (device trust, impossible-travel detection, session length limits) are enforced, since the attackers maintain sessions for eight hours and use residential proxies to mimic legitimate sign-ins. The abuse of Google Meet redirect URLs and S3-hosted HTML as redirect hops means email filters that trust Google/S3 domains will not catch the initial lure.

Discussion angle

Why MFA is no longer a sufficient control when attackers proxy the entire auth flow in real time, and what conditional access or phishing-resistant auth (FIDO2/passkeys) your org should actually be enforcing on M365.

Top