Threat actors utilized adversary-in-the-middle phishing to bypass Microsoft 365 multi-factor authentication and hijack finance employee mailboxes. By capturing authenticated session cookies through fake sign-in pages, attackers executed business email compromise campaigns without triggering typical login alerts. This method allows unauthorized access and payment theft without malware installation, posing a significant risk to financial institutions relying on standard email security protocols.
Relevant URL: https://cybersecuritynews.com/hackers-bypass-microsoft-365-mfa/