/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says a phishing campaign targeted 10K+ organizations since September 2021 by hijacking Office 365's authentication process even on accounts using MFA

Campaign that steals email has targeted at least 10,000 organizations since October.  —  On Tuesday, Microsoft detailed …

Ars Technica Dan Goodin

Context & Ripple Effects

Microsoft's disclosure sits alongside its phishing-as-a-service operation finding from the same period, showing that scalable phishing tooling was already being sold with extensive templates. The important distinction here is that the campaign targeted the authentication path rather than simply trying to collect passwords.

Later Microsoft reporting on OAuth-app abuse for phishing and spam and its removal of fraudulent partner accounts used for malicious OAuth apps extends the arc: email theft campaigns increasingly exploit trusted identity and application mechanisms around Microsoft cloud accounts.

First-order effects

  • Organizations targeted by the campaign face email compromise even where affected accounts use MFA, because the attack hijacks the Office 365 authentication process rather than relying on a password alone.
  • Microsoft and Office 365 administrators must treat the authentication flow itself as an attack surface, not MFA enrollment as a complete control against phishing-driven email theft.

Second-order effects

  • Microsoft's cloud customers must scrutinize consented applications and authentication activity alongside conventional phishing defenses, a pressure reinforced by the later OAuth-app misuse reports.
  • Phishing operators gain a route to higher-value email access by targeting authenticated sessions and connected apps, raising the stakes for Microsoft controls over identity and partner ecosystems.

Third-order effects

  • If authentication-hijacking and malicious-app campaigns continue to recur, enterprise email security will shift from credential protection toward governance of sessions, application consent, and trusted-account pathways.
  • Microsoft's repeated disclosures point to a structural contest over cloud identity: platform safeguards and customer identity practices must adapt as attackers target the mechanisms designed to make login more secure.

The trend: Cloud phishing is evolving from password theft toward abuse of authenticated sessions and identity-linked applications that can sidestep MFA's narrow protection against credential reuse.

Discussion

  • @msftsecintel @msftsecintel on x
    Attackers behind a large-scale adversary-in-the-middle (AiTM) phishing campaign used stolen credentials and session cookies to skip the authentication process and perform follow-on business email compromise (BEC) campaigns against other targets. Details: https://www.microsoft.com…
  • @sarahhandler Sarah Handler on x
    Awesome new @Microsoft blog out on adversary-in-the-middle (AiTM) phishing and cookie replay attacks in BEC campaigns. One more reason to move towards phish-resistant MFA! https://www.microsoft.com/...
  • @campuscodi Catalin Cimpanu on x
    Microsoft has a report out on a BEC gang that used adversary-in-the-middle (AiTM) phishing sites (aka reverse proxies) to collect authentication cookies from targeted orgs https://www.microsoft.com/... https://twitter.com/...