Identity · 52 days ago
The break is the live Microsoft 365 session, not the password. Once the attacker captures an MFA-approved session, they can keep using Microsoft Graph to read payroll and finance mail without setting off the usual sign-in alarms, so a password reset can miss the access that is still active.
Arctic Wolf says the campaign has hit hundreds of organizations and produced successful intrusions across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe. It uses residential proxies to make malicious sign-ins look like ordinary consumer traffic and refreshes compromised sessions about every eight hours to keep them valid.
That makes the compromise durable after the phishing event ends. The same pattern can keep working anywhere long-lived sessions and API access are trusted more than the original login event.
1 source covering this story
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
AitM phishing hijacks Microsoft 365 accounts, then uses residential proxies and Microsoft Graph API access to collect payroll and finance email.
Part of the PlainSec briefing for 2026-08-08