What happened
Microsoft disclosed in July 2022 that a large-scale adversary-in-the-middle phishing campaign had targeted more than 10,000 organisations since September 2021. The attackers used proxy infrastructure to sit between victims and the real Microsoft sign-in page, stealing session cookies and thereby bypassing multi-factor authentication even where it was enabled. Compromised mailboxes were then used to run business email compromise and payment fraud against the victims' counterparties.
How the deception worked
Targets received phishing emails, often disguised as voice message notifications, linking to a proxy server that displayed the genuine Microsoft log-in page. The victim typed their real password and completed their real MFA challenge, both of which were passed straight through to Microsoft, so the experience was indistinguishable from a normal log-in. The proxy captured the resulting session cookie, which the attacker replayed to enter the mailbox without any further authentication. Microsoft observed operators moving to payment fraud within minutes, hunting invoice threads, adding hidden mailbox rules to suppress replies and emailing the victim's suppliers with altered bank details.
The control that would have caught it· our reading, not a claim from the sources
Standard MFA is not proof against session-token theft; phishing-resistant credentials bound to the origin, plus conditional access on device compliance and token protection, are what break the proxy.
Sources (2)
- From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraudMicrosoft Security Blog·microsoft.comOpen ↗
- Microsoft: 10,000 Organizations Targeted in Large-Scale Phishing CampaignSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.