A single phishing email was enough to give attackers access to a finance employee’s Microsoft 365 account and redirect vendor payments. The incident shows how criminals can bypass multi-factor authentication without installing malware or breaking into a company device.
The attackers used a targeted HR-themed message that claimed a paid-time-off request had been denied.
The email directed the recipient to review “conflicting dates,” but the link led through several redirects to a fake Microsoft 365 sign-in page designed to capture an already authenticated session.
Analysts from TrendAI identified the activity as a cloud-only business email compromise campaign. The attackers did not deploy an infostealer, remote-access tool, or other malware.
Instead, they relied on stolen browser session data, mailbox access, and carefully timed payment-change emails to move money to bank accounts they controlled.
TrendAI said in a report shared with Cyber Security News (CSN) that the case highlights a growing weakness in identity-focused attacks. MFA can stop many password theft attempts, but it does not always protect an account when a victim is tricked into completing a real login through an attacker-controlled relay.
Similar Microsoft 365 session theft campaigns have shown that attackers increasingly target authenticated browser sessions rather than passwords alone.
The attack began with a personalized “PTO Request Denied” email sent to a finance user. It used the employee’s name, role, and organization details, making the message appear more believable than a mass phishing attempt.
The button in the email used a SendGrid tracking link before sending the victim through a chain of attacker-controlled websites.
At the final destination, the victim saw a counterfeit Microsoft 365 sign-in page. This page acted as an adversary-in-the-middle, or AiTM, relay.
It passed the user’s sign-in details and MFA approval to the legitimate service in real time, then captured the authenticated session cookie created after the login succeeded.
That session cookie was the key to the intrusion. Rather than repeatedly asking for passwords or MFA codes, the attackers replayed the valid session from commercial VPN infrastructure and appeared to Microsoft 365 as the already authenticated employee.
This tactic is also central to recent AiTM phishing attacks targeting enterprise users, where criminals intercept live web sessions instead of simply collecting credentials.
Investigators found sign-ins from Amsterdam and Los Angeles roughly one minute apart, a travel pattern that could not have been legitimate.
Microsoft 365 telemetry showed MFA as previously satisfied, no new challenge, no failed login activity, and no conditional-access controls applied to the replayed session.
The attackers then accessed Exchange Online, SharePoint, Microsoft 365 Search, and a shared accounts-payable mailbox through the compromised user’s existing permissions.
This gave them access to real invoices, payment conversations, and vendor information they could use to make fraudulent requests look routine.
The payment diversion scheme unfolded in two phases over about 30 days. First, the attackers impersonated a vendor’s accounts-payable contact through a free webmail account.
They referenced approximately 20 legitimate outstanding invoices, requested a shift from paper checks to ACH payments, and supplied fraudulent authorization and tax documents.
The attackers kept the email thread active for more than three weeks. Their steady follow-ups pressured the finance team to update the vendor’s banking details, while the stolen mailbox access gave them visibility into internal conversations and payment status.
This type of invoice fraud closely resembles the BEC payment diversion attack chain, where criminals monitor legitimate business discussions before inserting fraudulent bank details.
In the second phase, the attackers impersonated a senior accounts-payable colleague using a look-alike domain. They sent internal-looking verification messages to push several vendor banking updates through the approval process.
The combined external vendor impersonation and internal employee impersonation made the fake requests appear independently confirmed.
To prevent discovery, the actors created three malicious inbox rules. The rules automatically archived and marked vendor collection notices as read, then stopped additional rules from processing those messages.
They also deleted emails that could have exposed the scam, allowing overdue-payment notices from the real vendor to remain unseen.
Organizations should investigate impossible-travel alerts alongside mailbox-rule changes, unusual token activity, and email deletions.
They should also enable token protection where available, revoke active sessions after suspected compromise, and require dual approval plus an out-of-band phone verification using a trusted number before changing vendor payment instructions. Phishing-resistant authentication methods can further reduce exposure to MFA bypass phishing techniques.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Email address | cs@bitcrazy[.]com | Sender address used for the phishing email |
| Domain | bitcrazy[.]com | Legitimately authorized SendGrid sending domain used in the campaign |
| Email address | human.resources@alerting-services[.]com | Displayed HR-themed sender identity used to mimic an internal mailbox |
| Domain | alerting-services[.]com | Domain included in the spoofed display identity |
| URL | u108265739[.]ct[.]sendgrid[.]net | SendGrid click-tracking link in the phishing redirect chain |
| Domain | mauthcopilot[.]com | Intermediate redirect domain |
| URL | portalmyadminsigninapps.experiencewithreliability[.]de/0xrcY/ | AiTM phishing destination leading to the fake Microsoft 365 sign-in page |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…