How Microsoft 365 Credential Theft Campaigns Bypass MFA and What You Can Do

Microsoft 365 users worldwide face phishing attacks using fake IT support and AiTM proxies that bypass MFA, stealing credentials for data theft. Learn how to defend against these threats.

How Microsoft 365 Credential Theft Campaigns Bypass MFA and What You Can Do
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What are the current threats targeting Microsoft 365 users?

Microsoft 365 users globally are being targeted by sophisticated phishing campaigns that impersonate IT help desk personnel. Attackers reach out via phone calls, Teams messages, and emails to deceive victims into handing over their login credentials, including multi-factor authentication (MFA) codes.

These campaigns use advanced phishing-as-a-service platforms, such as BigBear 2.0, which operate as attacker-in-the-middle (AiTM) proxies. This method intercepts both passwords and session cookies, enabling attackers to bypass traditional MFA protections and gain unauthorized access.

How do attackers bypass multi-factor authentication on Microsoft 365?

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion  Attacks
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Instead of simply stealing passwords, these attackers deploy AiTM proxy frameworks that sit between the victim and Microsoft’s authentication servers. When users enter their credentials and MFA codes on counterfeit login pages, the proxy relays that information in real-time to the legitimate service, effectively hijacking the session.

This means that even strong MFA protections, like one-time passcodes, can be compromised if the verification process is intercepted and replayed by the attacker. This attack vector enables unauthorized access without triggering typical security alerts tied to failed login attempts.

What are the consequences of compromised Microsoft 365 accounts?

Once attackers gain access, their primary goal is to exfiltrate sensitive information from services like Outlook, Teams, SharePoint, and OneDrive. Unlike ransomware attacks, which encrypt data for extortion, these campaigns focus on stealing and potentially leaking confidential data.

Thousands of credentials—including complete MFA-bypassed authentications and session cookies—have already been captured worldwide, affecting organizations across multiple sectors such as healthcare, finance, construction, and property management.

What defenses can organizations implement against these phishing campaigns?

BigBear 2.0 Phishing Targets M365 | CyPro
BigBear 2.0 Phishing Targets M365 | CyPro

Mitigating these risks requires a multi-layered approach:

  • Phishing-resistant MFA: Use authentication methods that cryptographically bind the login to the real website. Technologies like FIDO2/WebAuthn, security keys (e.g., YubiKeys), and passkeys are effective because they cannot be forwarded or reused by attackers.
  • Conditional Access policies: Restrict access based on conditions like user location, device compliance, or network risk to limit attacker opportunities even if credentials are compromised.
  • Access limitations: Limit users’ ability to bulk download or share sensitive data from SharePoint or OneDrive, reducing the impact of compromised accounts.
  • User education: Train employees to recognize suspicious calls or emails claiming to be IT staff and to avoid entering credentials on pages reached via unsolicited links.
  • Anomaly detection: Deploy monitoring tools to detect unusual behaviors such as token replay from residential proxies, unexpected mailbox harvesting, or bulk SharePoint activity.

Why is phishing-resistant MFA a critical upgrade?

Standard MFA methods relying on one-time codes sent via text or authenticator apps are vulnerable to interception in AiTM attacks. Phishing-resistant MFA methods employ cryptographic protocols that verify both the identity of the user and the authenticity of the service requesting authentication.

This means even if an attacker tricks a user into interacting with a phishing site, the authentication cannot be

React to this story

Related Posts