Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments
Brief
A single phishing email was enough to give attackers access to a finance employee’s Microsoft 365 account and redirect vendor payments. The incident shows how criminals can bypass multi-factor authentication without installing malware or breaking into a company device.
The attackers used a targeted HR-themed message that claimed a paid-time-off request had been denied.
The email directed the recipient to review “conflicting dates,” but the link led through several redirects to a fake Microsoft 365 sign-in page designed to capture an already authenticated session.
Analysts from TrendAI identified the activity as a cloud-only business email compromise campaign. The attackers did not deploy an infostealer, remote-access tool, or other malware.
