Threat Intelligence

Phishing Attack Hijacks Microsoft 365 Accounts to Spy on Payroll and Finance Emails

The Hacker News · 7 Aug 2026
Key Takeaway Enable multi-factor authentication with phishing-resistant methods and train staff to verify any changes to payroll or payment details through a separate, trusted communication channel.

Security researchers have identified an active, widespread phishing campaign targeting Microsoft 365 users with the goal of hijacking accounts and identifying staff involved in financial processes such as payroll and invoicing. The attackers use a technique known as adversary-in-the-middle (AitM), which allows them to intercept login sessions in real time, effectively bypassing standard password protections.

What makes this campaign particularly hard to detect is its use of residential proxies. These make malicious login attempts appear as if they're coming from ordinary home internet connections rather than suspicious overseas servers, helping the attackers slip past security systems designed to flag unusual sign-in locations. Once inside an account, attackers can monitor email traffic to find employees handling money matters, setting the stage for follow-up scams such as fraudulent invoice changes or payroll redirection.

This campaign highlights a growing trend where email compromise is used not for immediate theft, but for reconnaissance ahead of more targeted financial fraud. Small businesses using Microsoft 365 should be aware that traditional login alerts based on unusual locations may not catch these more sophisticated attacks.

Microsoft 365 Phishing Business Email Compromise

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.