Precision LogicsReliable IT • Secure Systems

Microsoft 365 Security • Precision Logics Insights

A new Microsoft 365 phishing campaign is hunting payroll and finance emails.

Attackers are using convincing sign-in pages to steal active sessions and quietly search mailboxes for payroll, banking, invoice, and benefits information.

Microsoft 365 phishing is getting quieter.

A campaign reported by Arctic Wolf Labs and The Hacker News is targeting Microsoft 365 accounts, then searching compromised mailboxes for payroll, banking, invoice, benefits, and other finance-related messages. The attackers are not necessarily sending obvious spam from the victim's account. In many cases, they appear to be collecting information and maintaining access while trying not to attract attention.

That matters for a small business. One compromised mailbox can expose payroll contacts, vendor payment details, employee information, open invoices, and the normal language people use when approving financial changes.

How the attack works

The campaign uses adversary-in-the-middle phishing, often shortened to AitM.

The victim receives a message such as a fake voicemail notification. The link eventually opens a convincing Microsoft sign-in page, but the attacker is sitting between the victim and Microsoft's real authentication service. The fake page relays the sign-in process while capturing the credentials, MFA response, and authenticated session.

This is why a user can complete MFA and still lose the session. The attacker is not simply guessing the password. They are stealing the authenticated browser session after the user signs in.

The campaign also uses trusted services in its redirect chain and residential internet connections near the victim's location. Those choices can make the sign-in look less unusual to automated filters.

MFA is still worth using. It stops many common account attacks. The lesson is that not every MFA method offers the same protection, and a convincing sign-in page can still trick a person into approving the wrong session.

Why payroll and finance mail is useful to an attacker

A mailbox can answer questions an attacker would otherwise have to guess:

  • Who can change direct-deposit information?
  • Who approves invoices or wire transfers?
  • Which vendors are expecting payment?
  • What wording does the owner or bookkeeper normally use?
  • When is payroll processed?

With that information, a fake payment request becomes much more believable. The attacker may wait for the right conversation instead of sending a sloppy message immediately.

What small businesses should do now

Treat unexpected voicemail links as untrusted

If an email says you have a voicemail, missed document, or account alert, open the known Microsoft 365 portal or the normal phone system directly. Do not use the link in the message unless you have independently verified it.

Strengthen authentication for sensitive accounts

Prioritize phishing-resistant sign-in methods for owners, administrators, payroll, HR, and finance users. Depending on the Microsoft 365 licensing and environment, that may include passkeys, FIDO2 security keys, or Windows Hello for Business. Microsoft Entra Conditional Access can require stronger authentication methods for sensitive resources, but it requires the right licensing and careful configuration.

Do not disable ordinary MFA while planning an upgrade. Ordinary MFA is still much better than password-only access.

Verify financial changes outside email

A request to change payroll, direct deposit, vendor banking, or payment instructions should be confirmed through a known phone number or an established approval process. Do not use the contact details supplied in the change request.

For higher-risk transactions, require a second person to review the change before money moves.

Review sign-ins and mailbox activity

Microsoft 365 administrators should review suspicious sign-ins, unfamiliar devices, unusual user agents, mailbox access, forwarding settings, and inbox rules. This campaign has used rotating residential addresses and recurring sessions, so a sign-in from the correct country or state is not enough by itself to prove that it is legitimate.

Pay extra attention to accounts that handle payroll, invoices, banking, benefits, or administrative work.

Know how to revoke access

Changing a password may not immediately end every active cloud session. Your response process should include revoking active sessions, resetting credentials, reviewing MFA methods, checking inbox and forwarding rules, examining recent account activity, and determining what information was accessed.

If financial information may have been exposed, notify the appropriate internal and financial contacts quickly. Preserve logs before they age out.

Separate daily work from administration

A Microsoft 365 global administrator should not use the same privileged account for ordinary email and web browsing. Separate administrative accounts reduce the chance that one phishing message turns into full tenant access.

A practical check for this week

Pick the Microsoft 365 accounts that can approve payments, change payroll, administer the tenant, or access sensitive employee data. For each one, answer four questions:

  1. Is MFA enabled?
  2. Is a phishing-resistant method available?
  3. Would someone notice a stolen session or unusual mailbox access?
  4. Is there a written process for verifying payment and payroll changes?

If any answer is “I don't know,” that is a good place to start. The goal is not to buy every security product. It is to make the most damaging account changes harder to fake and easier to detect.

Sources and further reading

Not sure how well your Microsoft 365 accounts are protected?

Precision Logics can help review sign-in security, administrator access, mailbox settings, backups, and recovery procedures in plain English.