{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or"},"incident":{"slug":"2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or","title":"Adversary-in-the-middle phishing campaign bypassed MFA at over 10,000 organisations","date":"2022-07-12","date_precision":"day","year":2022,"victim_org":"More than 10,000 organisations targeted (Microsoft-tracked campaign)","sector":"Technology","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Business Email Compromise","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Wire Fraud / Financial Loss","Data Breach"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.","how_it_worked":"Targets received phishing emails, often disguised as voice message notifications, linking to a proxy server that displayed the genuine Microsoft log-in page. The victim typed their real password and completed their real MFA challenge, both of which were passed straight through to Microsoft, so the experience was indistinguishable from a normal log-in. The proxy captured the resulting session cookie, which the attacker replayed to enter the mailbox without any further authentication. Microsoft observed operators moving to payment fraud within minutes, hunting invoice threads, adding hidden mailbox rules to suppress replies and emailing the victim's suppliers with altered bank details.","lessons":"Standard MFA is not proof against session-token theft; phishing-resistant credentials bound to the origin, plus conditional access on device compliance and token protection, are what break the proxy.","confidence":"Confirmed","sources":[{"title":"From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud","url":"https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/","publisher":"Microsoft Security Blog"},{"title":"Microsoft: 10,000 Organizations Targeted in Large-Scale Phishing Campaign","url":"https://www.securityweek.com/microsoft-10000-organizations-targeted-large-scale-phishing-campaign/","publisher":"SecurityWeek"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-adversary-in-the-middle-phishing-campaign-bypassed-mfa-at-over-10-000-or"}}