PGH Networks

Phishing Kits Bypassing Microsoft 365 MFA: What SMBs Should Do Now

July 18, 2026· PGH Networks Team· 4 min readCloud & Microsoft 365
Phishing Kits Bypassing Microsoft 365 MFA: What SMBs Should Do Now

If your team relies on Microsoft 365 for email, files, and Teams — and virtually every business we work with does — a fresh round of phishing activity deserves your attention. Attackers are no longer just stealing passwords; they're building purpose-made toolkits designed to sail right past the multi-factor authentication (MFA) prompt you've been trusting to save you.

What happened

According to reporting from BleepingComputer, security researchers have identified two new phishing kits — dubbed Jalisco and OmegaLord — being used in active campaigns against Microsoft 365 accounts. What sets them apart is that they're built specifically to defeat MFA, not just harvest usernames and passwords.

The specific evasion techniques, distribution channels, and victim counts are still being detailed by researchers, and we'd encourage anyone doing deeper due diligence to read the source directly and watch for follow-up indicators of compromise (IOCs) from Microsoft and the broader threat-intel community. What we can say with confidence: MFA-bypass phishing is not theoretical anymore — it's a productized, kit-driven business.

black key padlock on chain-link fence near road with cars running in time lapse photography

Why this matters for Pittsburgh SMBs

For a 10–200-person firm in Pittsburgh, the risk profile here is not abstract. Most of our clients — CPA firms heading into another busy season, law firms handling privileged matter, healthcare practices with PHI, manufacturers with customer IP, and defense subcontractors working toward or maintaining CMMC — live inside Microsoft 365 all day. An attacker who successfully sidesteps MFA doesn't just get an inbox. They get:

  • Email that can be weaponized against your clients and vendors. Wire-fraud and invoice-redirect scams almost always start with a legitimate, compromised mailbox sending from a trusted domain.
  • SharePoint and OneDrive access. Engagement letters, matter files, patient records, drawings, controlled unclassified information (CUI) — whatever your business stores, they can browse and exfiltrate.
  • A foothold to pivot. Once inside a tenant, attackers commonly create inbox rules to hide their tracks, register their own MFA method, and enroll rogue OAuth apps that survive a password reset.

For regulated verticals, one compromised M365 account can trigger real reporting obligations: HIPAA breach notification, state data-breach laws (Pennsylvania's included), FTC Safeguards Rule incident reporting for financial-services firms with 500+ affected consumers, SOC 2 incident disclosure to auditors and customers, and DFARS/CMMC 72-hour reporting for defense contractors. "We had MFA on" is no longer, by itself, a defense.

The uncomfortable truth is that traditional MFA — a code from an app or a text message — was designed to stop password spraying and credential stuffing. It was never designed to stop a real-time proxy that relays your login and steals your session cookie. That's the game these kits are playing.

What to do about it this week

You don't need to overhaul everything. You do need to close the specific doors these kits walk through. Here's a practical list you can start on in the next few business days:

  1. Move toward phishing-resistant MFA. Where your license allows, enable Microsoft Authenticator with number matching at a minimum, and start piloting FIDO2 security keys or Windows Hello for Business for admins, finance, and executives. These methods break the token-relay technique these kits depend on.
  2. Turn on (or verify) Conditional Access policies. Block legacy authentication, require compliant or hybrid-joined devices for M365 access where feasible, and add sign-in risk and user-risk policies via Entra ID Protection. Geo-blocking countries you don't do business in is a quick win.
  3. Hunt for malicious inbox rules and OAuth grants. Attackers routinely create rules that auto-delete or forward messages containing words like "invoice," "wire," or "password." Audit consented third-party apps in Entra and revoke anything unfamiliar.
  4. Shorten session lifetimes for high-risk roles. Global admins, finance staff, and partners should be forced to re-authenticate more often. Long-lived tokens are exactly what stolen session cookies exploit.
  5. Run a targeted phishing simulation and refresher. Focus the training on the specific pattern these kits use: a legitimate-looking Microsoft login page reached via a link in an email, a shared document notification, or a Teams message. The tell is almost always the URL.
  6. Confirm your logging is on and retained. Unified Audit Log, mailbox auditing, and Entra sign-in logs should be enabled with at least 90 days of retention (longer for regulated firms). If you get breached, this is what tells you what happened.
  7. Rehearse the "account takeover" playbook. Who revokes sessions? Who resets MFA methods? Who notifies clients or your compliance officer? A 30-minute tabletop this month is cheaper than a real one in January.

How PGH Networks helps

This is exactly the kind of threat we're built to get in front of for Pittsburgh-area businesses. Our team manages Microsoft 365 and Entra ID hardening, Conditional Access design, phishing-resistant MFA rollouts, 24/7 security monitoring, and the compliance documentation your auditors, insurers, and prime contractors are going to ask for — whether that's HIPAA, SOC 2, CMMC, or FTC Safeguards. If you're not certain where your tenant stands against the controls above, let's schedule a 30-minute M365 security review — call 724.888.7007 or reach us through the contact form and get a clear picture before an attacker gets one first.

Share

Related reading

Azure Consulting in Pittsburgh, PA

Azure consulting in Pittsburgh, PA for small and mid-market firms: migration, security, FinOps, and Copilot enablement from a local team. Talk to an engineer.