Cyber attackers have discovered a new way to hijack Microsoft 365 accounts, using a sophisticated phishing tactic that exploits a weakness in the platform’s authentication mechanism. Dubbed “AitM” (Authentication into Mail), this campaign has already compromised numerous high-profile organizations and individuals, with reports suggesting that payroll and finance emails are being intercepted for malicious purposes.
At its core, AitM works by tricking Microsoft 365 users into authenticating to a fake login page that mimics the real thing. Once an unsuspecting user enters their credentials, the attackers can access the victim’s account and use it to send emails on behalf of the compromised user. This is particularly concerning when it comes to payroll and finance-related communications, as these types of emails often contain sensitive information.
The scope of the AitM campaign is still unclear, but it’s understood that several prominent companies have been affected, including some in the financial and healthcare sectors. According to reports, attackers are using their newfound access to intercept emails related to financial transactions, salary payments, and other sensitive matters. This not only compromises the security of individual accounts but also puts entire organizations at risk.
A closer look at AitM reveals that it leverages a combination of social engineering tactics and clever manipulation of Microsoft 365’s authentication protocol. Attackers are using sophisticated phishing kits to create convincing fake login pages, complete with authentic-looking Microsoft branding and logos. When an unsuspecting user enters their credentials on this fake page, the attackers can then access the victim’s account via a technique known as “cross-domain privilege escalation.” This allows them to bypass security measures that might otherwise prevent unauthorized access.
The implications of AitM are far-reaching and unsettling. Not only do compromised accounts pose a direct threat to individuals and organizations, but they also create opportunities for further exploitation by attackers. In the words of one cybersecurity expert: “Once an attacker has control over someone’s Microsoft 365 account, it’s like having a master key to access all their emails and sensitive data.”
In light of this emerging threat, it’s essential that Microsoft 365 users take immediate action to protect themselves. One simple yet effective step is to enable two-factor authentication (2FA) on all accounts, which can significantly reduce the risk of AitM-style attacks. Additionally, being cautious when clicking on links or entering credentials online – especially if they appear in an email or message – can go a long way in preventing these types of phishing attempts from succeeding. By staying vigilant and taking proactive measures to secure their digital lives, individuals and organizations can significantly reduce the risk of falling victim to AitM attacks.
Source: The Hacker News — 2026-08-07