# Phishing Scheme Bypasses Microsoft 365 MFA to Redirect Vendor Payments

*Published August 21, 2026*
*Source: [https://cybersecuritynews.com/hackers-bypass-microsoft-365-mfa/](https://cybersecuritynews.com/hackers-bypass-microsoft-365-mfa/)*

## Executive Summary

A phishing attack bypassed Microsoft 365 multi-factor authentication, allowing attackers to hijack a finance employee's account and redirect vendor payments. This incident underscores the need for stronger security measures to combat identity-focused threats that exploit authenticated session data.

## Article

A sophisticated phishing attack recently targeted a finance employee's Microsoft 365 account, successfully redirecting vendor payments. The attackers used a cleverly crafted email that mimicked a human resources notification, falsely informing the employee that a paid-time-off request had been denied. This phishing email led the victim through a series of redirects to a fake Microsoft 365 sign-in page that captured an already authenticated session.

TrendAI analysts identified this as a cloud-only business email compromise campaign, highlighting a growing vulnerability in identity-focused attacks. The attackers operated without deploying malware, relying instead on stolen browser session data and timely emails to alter bank account information for payments. Through this method, they bypassed multi-factor authentication, exploiting a session cookie to impersonate the authenticated user.

Attackers began by sending a personalized email using the employee's details to increase credibility. The email contained a SendGrid tracking link, which led to a counterfeit Microsoft 365 login page. This page acted as an adversary-in-the-middle relay, capturing the session cookie that allowed the attackers to access the employee's account without needing further authentication.

Once inside, the attackers accessed various Microsoft 365 services, including Exchange Online and SharePoint, to gather information on invoices and vendor communications. They manipulated these communications to divert payments, impersonating both external vendors and internal employees to create an illusion of legitimacy. They further concealed their activities by setting mailbox rules to automatically archive and mark certain emails as read, preventing detection.

Organizations are advised to enhance their security measures by monitoring for unusual activity such as impossible travel alerts and changes in mailbox rules. Implementing token protection, revoking suspicious sessions, and requiring multi-step verification for financial transactions can mitigate such attacks. Phishing-resistant authentication methods can also help reduce vulnerability to these sophisticated threats.
