Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
- ID
- 11901
- Status
- summarized
- Published
- 07 Aug 2026, 6:38 PM
- Fetched
- 07 Aug 2026, 7:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 07 Aug 2026, 7:49 PM
- Tags
- Audience
- developerssaas_founders
What happened
Arctic Wolf Labs reports a widespread AitM phishing campaign hijacking Microsoft 365 accounts via voicemail-themed emails, using a six-stage redirect chain through Google Meet, Google Ads, and Amazon S3 to bypass reputation filters. Compromised sessions are maintained at roughly eight-hour intervals using residential proxies, and attackers target employees in financial workflows to reroute payroll payments. Hundreds of organizations were hit last month across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe.
Why it matters
If your organization runs on Microsoft 365, MFA alone does not stop this attack—AitM proxies capture credentials and MFA codes in real time. Founders and IT leads should verify whether conditional access policies (device trust, impossible-travel detection, session length limits) are enforced, since the attackers maintain sessions for eight hours and use residential proxies to mimic legitimate sign-ins. The abuse of Google Meet redirect URLs and S3-hosted HTML as redirect hops means email filters that trust Google/S3 domains will not catch the initial lure.
Discussion angle
Why MFA is no longer a sufficient control when attackers proxy the entire auth flow in real time, and what conditional access or phishing-resistant auth (FIDO2/passkeys) your org should actually be enforcing on M365.