Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
What happened
A widespread phishing campaign is using adversary-in-the-middle (AitM) techniques and residential proxies to hijack Microsoft 365 accounts. Attackers are specifically targeting personnel involved in financial workflows to exfiltrate payroll and finance emails.
Why it ranks #1
Confirmed active exploitation of identity infrastructure with immediate enterprise exposure, placing it in the highest urgency tier.
Who should care
CISOs and security leaders, Identity and access teams, SOC and incident response teams
What to do
Enable phishing-resistant MFA and monitor for anomalous sign-ins from residential proxy ranges.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed