Microsoft 365 phishing steals vendor payments

Published August 20, 2026

Attackers used a fake Microsoft 365 login page to steal a finance worker's active login session, skipping the need to beat multi-factor authentication. Once inside the mailbox, they quietly rerouted a company's vendor payments to their own bank account.

Report priority
Medium
Targets
Exchange Online+2 more

How it works

A phishing email impersonating an HR PTO notice sent the victim through a legitimate-looking link to a fake Microsoft 365 login page that sat between the victim and the real service, capturing the session cookie created right after the victim logged in and completed MFA.

What to do

Check whether any Microsoft 365 sign-ins show 'MFA previously satisfied' from unfamiliar locations close together in time, and review all inbox rules, including hidden ones, for rules that auto-archive or mark messages as read.

Enable Conditional Access and token protection, revoke suspicious sessions, remove any unauthorized inbox rules, and verify recent vendor bank-account changes by phone before paying.

Technical details

Affected software: Exchange Online, SharePoint, Outlook

A finance employee gets an email titled PTO Request Denied with a View PTO Conflicting Dates button. Clicking it passes through a tracking link and redirects before landing on a counterfeit Microsoft 365 login page. The victim logs in and passes MFA, and the attacker's server captures that session and reuses it to open the real mailbox from a different location without triggering a new MFA prompt.

The attackers ran an adversary-in-the-middle phishing kit that proxied the real Microsoft 365 login flow, letting the victim complete authentication and MFA normally while the kit captured the resulting session cookie. Because token protection and Conditional Access were not applied, the stolen cookie let the attacker replay an already-authenticated session from separate IP addresses in Amsterdam and Los Angeles about a minute apart, with no new MFA challenge. From there they used the finance user's delegated permissions in Exchange Online and SharePoint and created three inbox rules that auto-archived and marked-as-read incoming vendor and internal messages, hiding the fraud while a two-stage vendor impersonation scheme diverted payments over about three weeks.