Session Theft Bypasses MFA and Sign-In Alerts

The break is the live Microsoft 365 session, not the password. Once the attacker captures an MFA-approved session, they can keep using Microsoft Graph to read payroll and finance mail without setting off the usual sign-in alarms, so a password reset can miss the access that is still active. Arctic Wolf says the campaign has hit hundreds of organizations and produced successful intrusions across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe. It uses residential proxies to make malicious sign-ins look like ordinary consumer traffic and refreshes compromised sessions about every eight hours to keep them valid. That makes the compromise durable after the phishing event ends. The same pattern can keep working anywhere long-lived sessions and API access are trusted more than the original login event.

Part of the PlainSec briefing for 2026-08-07

Every edition of this story: Session Theft Bypasses MFA and Sign-In Alerts

Sources