A single phishing email gave attackers full access to a finance employee's Microsoft 365 account — no malware required. The attack used a fake "PTO Request Denied" message to lure the victim through a chain of redirects to a counterfeit Microsoft sign-in page that captured their authenticated session cookie in real time, bypassing MFA entirely.
With that stolen session, attackers accessed invoices, payment threads, and a shared accounts-payable mailbox. Over 30 days, they impersonated a vendor and an internal colleague to redirect payments to fraudulent bank accounts — while hidden inbox rules buried any alerts. Organizations should enforce out-of-band payment verification and token protection immediately.
Source: Cybersecurity News