Cyber Security News

Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments

A single phishing email was enough to give attackers access to a finance employee’s Microsoft 365 account and redirect vendor payments. The incident shows how criminals can bypass multi-factor authentication without installing malware or breaking into a company device.

The attackers used a targeted HR-themed message that claimed a paid-time-off request had been denied.

The email directed the recipient to review “conflicting dates,” but the link led through several redirects to a fake Microsoft 365 sign-in page designed to capture an already authenticated session.

Analysts from TrendAI identified the activity as a cloud-only business email compromise campaign. The attackers did not deploy an infostealer, remote-access tool, or other malware.

Instead, they relied on stolen browser session data, mailbox access, and carefully timed payment-change emails to move money to bank accounts they controlled.

TrendAI said in a report shared with Cyber Security News (CSN) that the case highlights a growing weakness in identity-focused attacks. MFA can stop many password theft attempts, but it does not always protect an account when a victim is tricked into completing a real login through an attacker-controlled relay.

End-to-end attack chain (Source – TrendAI)

Similar Microsoft 365 session theft campaigns have shown that attackers increasingly target authenticated browser sessions rather than passwords alone.

Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox

The attack began with a personalized “PTO Request Denied” email sent to a finance user. It used the employee’s name, role, and organization details, making the message appear more believable than a mass phishing attempt.

The button in the email used a SendGrid tracking link before sending the victim through a chain of attacker-controlled websites.

At the final destination, the victim saw a counterfeit Microsoft 365 sign-in page. This page acted as an adversary-in-the-middle, or AiTM, relay.

It passed the user’s sign-in details and MFA approval to the legitimate service in real time, then captured the authenticated session cookie created after the login succeeded.

That session cookie was the key to the intrusion. Rather than repeatedly asking for passwords or MFA codes, the attackers replayed the valid session from commercial VPN infrastructure and appeared to Microsoft 365 as the already authenticated employee.

This tactic is also central to recent AiTM phishing attacks targeting enterprise users, where criminals intercept live web sessions instead of simply collecting credentials.

Investigators found sign-ins from Amsterdam and Los Angeles roughly one minute apart, a travel pattern that could not have been legitimate.

Microsoft 365 telemetry showed MFA as previously satisfied, no new challenge, no failed login activity, and no conditional-access controls applied to the replayed session.

The attackers then accessed Exchange Online, SharePoint, Microsoft 365 Search, and a shared accounts-payable mailbox through the compromised user’s existing permissions.

The two-phase vendor payment-diversion BEC (Source – TrendAI)

This gave them access to real invoices, payment conversations, and vendor information they could use to make fraudulent requests look routine.

Fraud Hidden Inside Mailboxes

The payment diversion scheme unfolded in two phases over about 30 days. First, the attackers impersonated a vendor’s accounts-payable contact through a free webmail account.

They referenced approximately 20 legitimate outstanding invoices, requested a shift from paper checks to ACH payments, and supplied fraudulent authorization and tax documents.

The attackers kept the email thread active for more than three weeks. Their steady follow-ups pressured the finance team to update the vendor’s banking details, while the stolen mailbox access gave them visibility into internal conversations and payment status.

This type of invoice fraud closely resembles the BEC payment diversion attack chain, where criminals monitor legitimate business discussions before inserting fraudulent bank details.

In the second phase, the attackers impersonated a senior accounts-payable colleague using a look-alike domain. They sent internal-looking verification messages to push several vendor banking updates through the approval process.

The “PTO Request Denied” spear-phishing email (Source – TrendAI)

The combined external vendor impersonation and internal employee impersonation made the fake requests appear independently confirmed.

To prevent discovery, the actors created three malicious inbox rules. The rules automatically archived and marked vendor collection notices as read, then stopped additional rules from processing those messages.

They also deleted emails that could have exposed the scam, allowing overdue-payment notices from the real vendor to remain unseen.

Organizations should investigate impossible-travel alerts alongside mailbox-rule changes, unusual token activity, and email deletions.

They should also enable token protection where available, revoke active sessions after suspected compromise, and require dual approval plus an out-of-band phone verification using a trusted number before changing vendor payment instructions. Phishing-resistant authentication methods can further reduce exposure to MFA bypass phishing techniques.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Email addresscs@bitcrazy[.]comSender address used for the phishing email
Domainbitcrazy[.]comLegitimately authorized SendGrid sending domain used in the campaign
Email addresshuman.resources@alerting-services[.]comDisplayed HR-themed sender identity used to mimic an internal mailbox
Domainalerting-services[.]comDomain included in the spoofed display identity
URLu108265739[.]ct[.]sendgrid[.]netSendGrid click-tracking link in the phishing redirect chain
Domainmauthcopilot[.]comIntermediate redirect domain
URLportalmyadminsigninapps.experiencewithreliability[.]de/0xrcY/AiTM phishing destination leading to the fake Microsoft 365 sign-in page

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

1 hour ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

3 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

3 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago