Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

An active AitM phishing campaign targets M365 accounts of payroll and finance staff to intercept financial communications — a refined BEC precursor requiring token-binding defences.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.

"The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

Editorial Analysis

Why it matters

By specifically targeting financial workflow personnel, attackers are refining BEC tactics with session-token theft, making phishing-resistant MFA and token-binding essential, not optional.

What to do

Enable Conditional Access token-binding and continuous access evaluation for M365 sessions, especially for finance teams.

Board brief

Phishing campaigns are now stealing live M365 sessions from finance staff, requiring stronger authentication controls to prevent funds diversion.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk