PGH Networks

Microsoft 365 AitM Phishing Is Hunting Your Payroll Inbox

August 8, 2026· PGH Networks Team· 4 min readCloud & Microsoft 365
Microsoft 365 AitM Phishing Is Hunting Your Payroll Inbox

What happened

Researchers are tracking an active, widespread phishing campaign that uses adversary-in-the-middle (AitM) techniques to hijack Microsoft 365 accounts, with the specific goal of identifying finance and payroll personnel and harvesting their email. According to reporting from feeds.feedburner.com, the attackers route malicious sign-ins through residential proxy networks so the logins blend in with ordinary consumer internet traffic, making them much harder to spot in conditional access logs.

AitM attacks work by placing a reverse-proxy phishing page between the victim and the real Microsoft 365 login. When the user enters credentials and completes MFA, the attacker captures the resulting session token and replays it, effectively walking around most standard MFA prompts. The referenced article does not publish a full list of indicators of compromise or a named threat actor, so those details are worth verifying directly with your security team or MSP before you build detections around them.

Linkedin data privacy settings on a smartphone screen

Why this matters for Pittsburgh SMBs

If you run a 10-200 person firm in Pittsburgh, and especially if you're in accounting, legal, healthcare, financial services, or defense manufacturing, you are exactly the profile this campaign is built to monetize. The attackers aren't after your Netflix password. They're after the mailbox of the controller who approves wire transfers, the payroll admin who runs the ADP or Paylocity file every other Thursday, or the CPA partner whose inbox contains client banking instructions during tax season.

A few specifics worth naming:

  • Business email compromise (BEC) still costs SMBs more than ransomware in many years. A hijacked M365 mailbox is often the first step: attackers watch email quietly for weeks, learn your invoicing cadence, then insert themselves into a real thread with new "updated" bank details.
  • Residential proxy traffic defeats naive geo-blocking. If your only conditional access rule is "block logins from outside the US," a proxy exit node in suburban Ohio will sail right through.
  • Compliance exposure compounds the loss. For HIPAA-covered practices, a compromised mailbox containing PHI is a reportable breach. For CMMC Level 2 defense contractors, a mailbox touching CUI triggers DFARS 7012 incident reporting inside 72 hours. For anyone under the FTC Safeguards Rule or SOC 2, "we didn't know they were in there" is not a defensible control narrative.

The takeaway: MFA alone is no longer the finish line. Session-token theft has been the dominant M365 attack pattern for two years running, and this campaign is a reminder that the tooling has only gotten more polished.

What to do about it this week

You don't need a six-month project to close the biggest gaps. Here's a practical checklist your internal IT lead or your managed IT provider can start on now:

  1. Turn on phishing-resistant MFA for finance, executive, and IT admin accounts. That means FIDO2 security keys or Windows Hello for Business, not SMS and not push-approval. Push fatigue is how most of these tokens get stolen in the first place.
  2. Enforce Entra ID conditional access with token protection and sign-in risk policies. Require compliant or hybrid-joined devices for access to Exchange Online and SharePoint. This is the single biggest lever against replayed session tokens.
  3. Shorten sign-in session lifetimes for high-risk roles (controllers, AP, HR/payroll, partners). A 90-day "stay signed in" window is a gift to attackers; a 1-day or 8-hour policy is not.
  4. Hunt for inbox rules that hide mail. Attackers almost always create a rule that auto-forwards or auto-deletes messages containing words like "invoice," "wire," "payroll," or "ACH." Run a tenant-wide audit today and set an alert for new forwarding rules going forward.
  5. Block legacy authentication and disable unused protocols (IMAP, POP, SMTP AUTH) at the mailbox level. AitM kits sometimes pivot to these once inside.
  6. Verify banking-change requests out of band. A written policy that says "any change to payment instructions requires a callback to a known number" prevents the actual wire loss even when the mailbox is compromised. Train AP and payroll on it this week.
  7. Confirm your EDR/MDR is watching identity, not just endpoints. Modern cybersecurity stacks correlate Entra ID sign-in events with endpoint behavior; if yours doesn't, that's a gap worth surfacing at your next steering meeting.

If you're regulated, add one more: document what you did. Whether you're preparing for a SOC 2 renewal, a HIPAA risk analysis, or a CMMC Level 2 assessment, evidence that you responded to a named, active threat is exactly the kind of artifact assessors want to see. Our compliance and CMMC engagements build that trail as a matter of routine.

Two small electronic devices on a wooden surface.

How PGH Networks helps

We run this playbook for Pittsburgh-area professional services, healthcare, and defense-contractor clients every day: hardening Microsoft 365 tenants, tuning conditional access, monitoring identity signals 24x7, and translating findings into the language your auditors and your leadership team actually need. If you want a second set of eyes on your M365 configuration, or a vCIO-led review of where finance and payroll workflows are exposed, our IT strategy team can be on a call this week.

Talk to us

Call 724.888.7007 or reach out through the contact form and we'll set up a short working session focused on your M365 tenant and your finance workflows, no sales theater.

Share

Related reading