A sophisticated phishing attack recently targeted a finance employee's Microsoft 365 account, successfully redirecting vendor payments. The attackers used a cleverly crafted email that mimicked a human resources notification, falsely informing the employee that a paid-time-off request had been denied. This phishing email led the victim through a series of redirects to a fake Microsoft 365 sign-in page that captured an already authenticated session.
TrendAI analysts identified this as a cloud-only business email compromise campaign, highlighting a growing vulnerability in identity-focused attacks. The attackers operated without deploying malware, relying instead on stolen browser session data and timely emails to alter bank account information for payments. Through this method, they bypassed multi-factor authentication, exploiting a session cookie to impersonate the authenticated user.
Attackers began by sending a personalized email using the employee's details to increase credibility. The email contained a SendGrid tracking link, which led to a counterfeit Microsoft 365 login page. This page acted as an adversary-in-the-middle relay, capturing the session cookie that allowed the attackers to access the employee's account without needing further authentication.
Once inside, the attackers accessed various Microsoft 365 services, including Exchange Online and SharePoint, to gather information on invoices and vendor communications. They manipulated these communications to divert payments, impersonating both external vendors and internal employees to create an illusion of legitimacy. They further concealed their activities by setting mailbox rules to automatically archive and mark certain emails as read, preventing detection.
Organizations are advised to enhance their security measures by monitoring for unusual activity such as impossible travel alerts and changes in mailbox rules. Implementing token protection, revoking suspicious sessions, and requiring multi-step verification for financial transactions can mitigate such attacks. Phishing-resistant authentication methods can also help reduce vulnerability to these sophisticated threats.


