CYBERSECURITYTRACKER
TRACKING7,256 stories in this site build1,517 vulnerability news stories in this site build
Permanent story citation

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4057

As cited

Copy frozen at (site build).

threat intel

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Researchers have identified an active phishing campaign using adversary-in-the-middle techniques to compromise Microsoft 365 accounts and extract emails related to payroll and finance operations. The attackers employ residential proxies to mask malicious sign-ins as legitimate consumer traffic.

Why it matters: Finance and HR teams using Microsoft 365 are targets for account takeover via phishing; practitioners should review sign-in logs for suspicious activity and enforce conditional access policies to block unusual login patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Researchers have identified an active phishing campaign using adversary-in-the-middle techniques to compromise Microsoft 365 accounts and extract emails related to payroll and finance operations. The attackers employ residential proxies to mask malicious sign-ins as legitimate consumer traffic.

Why it matters: Finance and HR teams using Microsoft 365 are targets for account takeover via phishing; practitioners should review sign-in logs for suspicious activity and enforce conditional access policies to block unusual login patterns.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary