Logo

Microsoft 365 Phishing Scam Targets Payroll Emails

If your business uses Microsoft 365 for email – and most small businesses in Gippsland do – you need to know about a phishing campaign currently doing the rounds. It’s not your average “click this dodgy link” scam. This one is specifically designed to hijack Microsoft 365 accounts and then quietly monitor emails to find out who handles payroll and finance, before striking with a fraudulent payment request. It’s sophisticated, it’s active right now, and it’s exactly the kind of attack that catches busy small business owners off guard.

What’s actually happening

Security researchers recently flagged a widespread email-driven phishing campaign using what’s called “adversary-in-the-middle” (AitM) techniques, as reported by The Hacker News. In plain English, this means the attacker sits invisibly between you and Microsoft when you log in. You type your username and password into what looks like a genuine Microsoft sign-in page, and behind the scenes the attacker’s system passes those details straight through to the real Microsoft 365 login – capturing your session in the process.

The clever (and nasty) part is that this technique can also intercept the session after multi-factor authentication (MFA) has been completed. So even if you’ve ticked the “we use MFA, we’re covered” box, this particular style of attack can still get through in some cases, because it’s stealing the active session rather than just the password.

Once inside, the attackers don’t necessarily act straight away. Instead, they use residential proxy networks to make their access look like normal, everyday login activity from a regular home internet connection – rather than something obviously suspicious like a login from overseas. This helps them stay hidden while they quietly search through mailboxes for anyone involved in financial workflows: bookkeepers, office managers, accounts payable staff, and business owners who approve payments.

Why this matters for small businesses specifically

Large enterprises typically have dedicated security teams monitoring login activity around the clock. Small and medium businesses in regional Victoria generally don’t – and that’s exactly why this type of attack is so effective against smaller operators. A local trades business, professional services firm, or retailer with one person handling the books is a much easier target than a company with a 24/7 security operations centre watching every login.

Once the attackers understand your business’s financial workflow, they can either sit and read invoices and payment approvals to time a fraudulent request perfectly, or they can send emails from your own compromised account to suppliers, clients, or your bookkeeper asking for a bank detail change or an “urgent” payment. Because it’s genuinely coming from your real email account, it often bypasses the usual red flags people are trained to look for.

Why MFA alone isn’t a silver bullet here

Multi-factor authentication is still one of the single best things a small business can do to protect itself, and we’re not suggesting you skip it. But this campaign is a good reminder that not all MFA is equal. Basic MFA methods – like a code sent via SMS or a simple “approve” push notification – can be intercepted or tricked by AitM techniques because the attacker is capturing the whole session, codes and all.

Phishing-resistant MFA methods, such as physical security keys (FIDO2) or number-matching authenticator apps with additional context, are much harder for this kind of attack to defeat, because there’s no code or approval prompt to intercept in the same way.

Practical steps you can take now

  • Turn on phishing-resistant MFA where possible, such as authenticator apps with number matching, rather than relying solely on SMS codes.
  • Set up a Conditional Access policy (available in Microsoft 365 Business Premium) that blocks sign-ins from unfamiliar locations or devices, or at least flags them for review.
  • Regularly review your mailbox rules for anything you didn’t create – attackers often set up hidden forwarding rules to silently copy emails to themselves.
  • Establish a strict rule that bank detail changes or payment requests are never actioned from an email alone – always verify by phone using a known, saved number, not one provided in the email.
  • Check your Microsoft 365 sign-in logs periodically for logins from unexpected locations or unusual times of day.
  • Disable legacy authentication protocols in Microsoft 365, which don’t support modern MFA and are a common weak point.
  • Train staff who handle finance and payroll specifically, since they are the deliberate target of this style of attack – not just general “don’t click links” training.

What to do if you suspect your account has been compromised

If you notice unusual sign-in activity, unexpected mailbox rules, or a supplier says they received a strange payment request from your business, act immediately. Change the affected password, revoke active sessions (this forces the attacker’s stolen session to be logged out), review and remove any suspicious mailbox rules, and check sent items for anything you didn’t send. It’s also worth notifying anyone you regularly invoice or pay, in case fraudulent emails have already gone out under your name.

The bigger picture

This campaign is a timely reminder that cybercriminals are increasingly patient and methodical. Rather than a smash-and-grab, they’re happy to sit inside a mailbox for days or weeks, learning how a business operates before striking at exactly the right moment – usually around payroll runs, supplier payments, or invoice due dates. For regional businesses that pride themselves on strong relationships with suppliers and clients, this kind of impersonation can be just as damaging to trust and reputation as it is financially.

The good news is that the defences here are well within reach for a small business – most of them are built into Microsoft 365 already, they just need to be switched on and configured properly. Taking an hour to review your MFA settings, mailbox rules, and sign-in logs now is a lot cheaper than dealing with a fraudulent payment or a damaged supplier relationship later.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions