What are the current threats targeting Microsoft 365 users?
Microsoft 365 users globally are being targeted by sophisticated phishing campaigns that impersonate IT help desk personnel. Attackers reach out via phone calls, Teams messages, and emails to deceive victims into handing over their login credentials, including multi-factor authentication (MFA) codes.
These campaigns use advanced phishing-as-a-service platforms, such as BigBear 2.0, which operate as attacker-in-the-middle (AiTM) proxies. This method intercepts both passwords and session cookies, enabling attackers to bypass traditional MFA protections and gain unauthorized access.
How do attackers bypass multi-factor authentication on Microsoft 365?
Instead of simply stealing passwords, these attackers deploy AiTM proxy frameworks that sit between the victim and Microsoft’s authentication servers. When users enter their credentials and MFA codes on counterfeit login pages, the proxy relays that information in real-time to the legitimate service, effectively hijacking the session.
This means that even strong MFA protections, like one-time passcodes, can be compromised if the verification process is intercepted and replayed by the attacker. This attack vector enables unauthorized access without triggering typical security alerts tied to failed login attempts.
What are the consequences of compromised Microsoft 365 accounts?
Once attackers gain access, their primary goal is to exfiltrate sensitive information from services like Outlook, Teams, SharePoint, and OneDrive. Unlike ransomware attacks, which encrypt data for extortion, these campaigns focus on stealing and potentially leaking confidential data.
Thousands of credentials—including complete MFA-bypassed authentications and session cookies—have already been captured worldwide, affecting organizations across multiple sectors such as healthcare, finance, construction, and property management.
What defenses can organizations implement against these phishing campaigns?
Mitigating these risks requires a multi-layered approach:
- Phishing-resistant MFA: Use authentication methods that cryptographically bind the login to the real website. Technologies like FIDO2/WebAuthn, security keys (e.g., YubiKeys), and passkeys are effective because they cannot be forwarded or reused by attackers.
- Conditional Access policies: Restrict access based on conditions like user location, device compliance, or network risk to limit attacker opportunities even if credentials are compromised.
- Access limitations: Limit users’ ability to bulk download or share sensitive data from SharePoint or OneDrive, reducing the impact of compromised accounts.
- User education: Train employees to recognize suspicious calls or emails claiming to be IT staff and to avoid entering credentials on pages reached via unsolicited links.
- Anomaly detection: Deploy monitoring tools to detect unusual behaviors such as token replay from residential proxies, unexpected mailbox harvesting, or bulk SharePoint activity.
Why is phishing-resistant MFA a critical upgrade?
Standard MFA methods relying on one-time codes sent via text or authenticator apps are vulnerable to interception in AiTM attacks. Phishing-resistant MFA methods employ cryptographic protocols that verify both the identity of the user and the authenticity of the service requesting authentication.
This means even if an attacker tricks a user into interacting with a phishing site, the authentication cannot be
