Phishing Attack Hijacks Microsoft 365 Accounts to Spy on Payroll and Finance Emails
Security researchers have identified an active, widespread phishing campaign targeting Microsoft 365 users with the goal of hijacking accounts and identifying staff involved in financial processes such as payroll and invoicing. The attackers use a technique known as adversary-in-the-middle (AitM), which allows them to intercept login sessions in real time, effectively bypassing standard password protections.
What makes this campaign particularly hard to detect is its use of residential proxies. These make malicious login attempts appear as if they're coming from ordinary home internet connections rather than suspicious overseas servers, helping the attackers slip past security systems designed to flag unusual sign-in locations. Once inside an account, attackers can monitor email traffic to find employees handling money matters, setting the stage for follow-up scams such as fraudulent invoice changes or payroll redirection.
This campaign highlights a growing trend where email compromise is used not for immediate theft, but for reconnaissance ahead of more targeted financial fraud. Small businesses using Microsoft 365 should be aware that traditional login alerts based on unusual locations may not catch these more sophisticated attacks.