Executive Summary
In August 2026, a widespread phishing campaign employing adversary-in-the-middle (AiTM) techniques targeted Microsoft 365 accounts across multiple sectors in the U.S., Canada, and Europe. Attackers used voicemail-themed phishing emails to direct victims to decoy pages that proxied legitimate Microsoft authentication flows, capturing credentials and multi-factor authentication (MFA) codes. The campaign utilized residential proxies to disguise malicious sign-ins, maintaining compromised sessions at regular intervals. Once access was obtained, threat actors focused on identifying personnel involved in financial workflows to collect related emails, potentially facilitating further financial fraud.
This incident underscores the evolving sophistication of phishing attacks, particularly those capable of bypassing MFA through AiTM methods. Organizations must enhance their security posture by implementing phishing-resistant MFA solutions, monitoring for anomalous sign-in activities, and educating employees about emerging phishing tactics to mitigate the risk of similar breaches.
Why This Matters Now
The increasing prevalence of AiTM phishing attacks highlights the urgent need for organizations to adopt advanced security measures that can effectively counteract sophisticated credential theft techniques and protect sensitive financial information.
Attack Path Analysis
The attack began with phishing emails leading victims to adversary-in-the-middle (AiTM) decoy pages that proxied legitimate Microsoft authentication flows, capturing credentials and multi-factor authentication (MFA) codes. Using the stolen session cookies, attackers maintained access to compromised accounts, enabling them to collect emails from payroll and HR personnel involved in financial matters. The attackers utilized residential proxies to disguise malicious sign-ins as ordinary consumer traffic, evading detection mechanisms. Automated activity maintained compromised sessions at approximately eight-hour intervals, allowing continuous access to sensitive information. The exfiltrated data was used to reroute salary payments to attacker-controlled accounts, resulting in financial losses for the affected organizations. The impact of the attack included unauthorized access to sensitive financial information and potential financial losses due to rerouted salary payments.
Kill Chain Progression
Initial Compromise
Description
Phishing emails led victims to AiTM decoy pages that proxied legitimate Microsoft authentication flows, capturing credentials and MFA codes.
MITRE ATT&CK® Techniques
Spearphishing Link
Adversary-in-the-Middle
Application Layer Protocol: Web Protocols
Email Collection: Remote Email Collection
Valid Accounts
Proxy: External Proxy
Valid Accounts: Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components are protected from known vulnerabilities by installing applicable security patches.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Implement controls, including encryption, to protect Nonpublic Information held or transmitted by the Covered Entity.
Control ID: 500.15
DORA – Ensure the security of network and information systems supporting critical or important functions.
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms to verify user identities.
Control ID: Identity and Access Management
NIS2 Directive – Implement appropriate technical and organizational measures to manage risks posed to the security of network and information systems.
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Microsoft 365 AitM phishing targeting payroll systems creates HIPAA compliance risks, threatening financial workflows and patient data protection infrastructure.
Higher Education/Acadamia
Educational institutions face Business Email Compromise attacks exploiting Microsoft 365 sessions to steal payroll data and compromise administrative financial operations.
Government Administration
Government agencies targeted by residential proxy-based phishing campaigns risk compromised financial workflows and sensitive administrative email data exfiltration.
Financial Services
AitM session hijacking threatens financial sector payroll systems, creating risks for payment rerouting attacks and regulatory compliance violations.
Sources
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emailshttps://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.htmlVerified
- Payroll Pirates: Strange New Tides in Business Email Compromisehttps://arcticwolf.com/resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/Verified
- Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromisehttps://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial credential theft via phishing, it could limit the attacker's ability to exploit these credentials within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to access sensitive financial communications by enforcing strict access controls between user accounts and sensitive data.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could limit the attacker's ability to move laterally within the network by enforcing strict segmentation and monitoring internal traffic patterns.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to maintain persistent access by providing comprehensive monitoring and control over cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit the attacker's ability to exfiltrate sensitive data by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF could reduce the overall impact of such attacks by limiting unauthorized access and data exfiltration, thereby minimizing financial losses.
Impact at a Glance
Affected Business Functions
- Payroll Processing
- Human Resources Management
- Financial Operations
- Email Communications
Estimated downtime: 3 days
Estimated loss: $50,000
Employee payroll records, financial transaction details, and sensitive HR communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement phishing-resistant MFA methods, such as FIDO2 or passkeys, to prevent AiTM attacks.
- • Deploy Zero Trust Segmentation to limit lateral movement and restrict access to sensitive resources.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Conduct regular security awareness training for employees to recognize and report phishing attempts.



