generalnews.media
importance 3/5 Exclusive

Microsoft 365 Phishing Bypasses MFA to Hijack Accounts for Payroll Data

Attackers used adversary-in-the-middle phishing to hijack Microsoft 365 accounts, bypassing multi-factor authentication and intercepting payroll and finance-related emails. The campaign targeted specific users to enable wire fraud and business email compromise. This underscores the risk of AitM attacks against common cloud email services.

Security

Sources (1)

security
← Back to home