Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Microsoft 365 to Divert Payments

Hackers Exploit Microsoft 365 to Divert Payments

Posted on August 20, 2026 By CWS

An unsettling cybersecurity breach has emerged as attackers successfully exploited Microsoft 365, bypassing multi-factor authentication (MFA) to redirect vendor payments. A single phishing email granted the hackers access to a finance employee’s account, allowing them to manipulate financial transactions without the need for malware or device infiltration.

Phishing Tactics Undermine Security

The breach began with a deceptive email themed around human resources, falsely stating that a paid-time-off request was denied. This personalized approach employed the employee’s specific details, making it appear more credible than typical mass phishing attempts. The email contained a link leading to a fraudulent Microsoft 365 login page, cleverly designed to capture authenticated sessions.

TrendAI analysts labeled this as a cloud-centered business email compromise operation. The attackers leveraged stolen browser session data and precise timing in their communications to reroute payments to their accounts. Notably, no traditional malware was used; instead, the focus was on exploiting authenticated browser sessions.

Session Hijacking Techniques

Key to the intrusion was the capture of an authenticated session cookie, allowing attackers to replay the session from VPN infrastructure, appearing as the legitimate employee. This method highlights a growing trend in session theft over mere password collection, as seen in other recent phishing campaigns targeting corporate users.

Investigators observed unusual login patterns, including geographically impossible sign-ins from Amsterdam and Los Angeles within a minute. Microsoft 365 logs showed satisfied MFA conditions with no failed login attempts, indicating the session replay attack.

Financial Manipulation and Mitigation

Through the compromised account, attackers accessed Exchange Online and other Microsoft 365 services, infiltrating a shared accounts-payable mailbox. Over 30 days, they impersonated vendors and employees, altering payment details to divert funds. They maintained email threads and created rules to hide fraudulent activities.

To counter such threats, organizations are advised to investigate unusual login activities, employ token protection, and enforce dual verification methods before altering payment instructions. Implementing phishing-resistant authentication can further mitigate risks associated with MFA bypass techniques.

Preventive Measures and Future Outlook

The incident underscores the need for heightened vigilance against identity-focused cyberattacks. Companies must enhance their security protocols, particularly in monitoring impossible travel alerts and unauthorized mailbox rule changes. By adopting comprehensive threat intelligence and reinforcing authentication procedures, businesses can better safeguard against sophisticated phishing schemes.

Cyber Security News Tags:business email compromise, Cybersecurity, enterprise security, financial fraud, identity-focused attacks, MFA bypass, Microsoft 365, payment diversion, phishing attack, phishing-resistant authentication, session hijacking

Post navigation

Previous Post: CDN Tsunami Threat: HTTP/3 Amplification in Focus
Next Post: Manic Malware Targets Android Devices with Innovative Techniques

Related Posts

Phishing Campaigns Exploit RMM Tools for Unauthorized Access Phishing Campaigns Exploit RMM Tools for Unauthorized Access Cyber Security News
Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT Beware of Typosquatted Malicious PyPI Packages That Delivers SilentSync RAT Cyber Security News
Global Threat: BADIIS Malware Compromises 1,800 Servers Global Threat: BADIIS Malware Compromises 1,800 Servers Cyber Security News
UEFI Shell Vulnerabilities Could Allow Hackers to Bypass Secure Boot on 200,000+ Laptops UEFI Shell Vulnerabilities Could Allow Hackers to Bypass Secure Boot on 200,000+ Laptops Cyber Security News
Strengthening Cybersecurity in 2026: Modern Data Protection Strengthening Cybersecurity in 2026: Modern Data Protection Cyber Security News
Critical VMware Vulnerability Exposes IT Systems to Risks Critical VMware Vulnerability Exposes IT Systems to Risks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Pentagon Data Breach and Major Cybersecurity Threats
  • Citrix NetScaler Vulnerability Exploited in Ongoing Attacks
  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Pentagon Data Breach and Major Cybersecurity Threats
  • Citrix NetScaler Vulnerability Exploited in Ongoing Attacks
  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark