Microsoft 365 Phishing Bypasses MFA to Hijack Accounts for Payroll Data
Attackers used adversary-in-the-middle phishing to hijack Microsoft 365 accounts, bypassing multi-factor authentication and intercepting payroll and finance-related emails. The campaign targeted specific users to enable wire fraud and business email compromise. This underscores the risk of AitM attacks against common cloud email services.