Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
thehackernews.com Aug 7, 2026

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

AI-summarised brief · reviewed before publication

Cybersecurity researchers identified a widespread adversary-in-the-middle phishing campaign targeting Microsoft 365 accounts to harvest payroll and finance emails. Arctic Wolf Labs reported the attack uses residential proxies to disguise malicious sign-ins as legitimate consumer traffic, impacting organizations in healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe. The campaign shares tactics with Microsoft’s tracked Storm-2755 and Storm-2657 threats. Attackers employ voicemail-themed emails leading to a six-stage redirection chain using trusted services like Google and Amazon S3 to bypass filters. This infrastructure captures credentials and multi-factor authentication codes while fingerprinting victim devices. Post-compromise, actors use geolocation data to select matching residential proxies, maintaining sessions via automated eight-hour intervals. They leverage the Microsoft Graph API to identify HR and finance personnel, subsequently accessing sensitive messages related to payroll and invoices to facilitate financial fraud.

💡 Why It Matters

  • · The campaign’s sophisticated use of trusted infrastructure and geolocation-matched proxies bypasses standard security controls, allowing attackers to maintain persistent access to sensitive financial data.
  • · This evolution in adversary-in-the-middle tactics demonstrates that traditional multi-factor authentication is insufficient against automated session hijacking, leaving organizations vulnerable to direct financial theft through compromised employee accounts.