If your business uses Microsoft 365 for email – and most small businesses in Gippsland do – you need to know about a phishing campaign currently doing the rounds. It’s not your average “click this dodgy link” scam. This one is specifically designed to hijack Microsoft 365 accounts and then quietly monitor emails to find out who handles payroll and finance, before striking with a fraudulent payment request. It’s sophisticated, it’s active right now, and it’s exactly the kind of attack that catches busy small business owners off guard.
Security researchers recently flagged a widespread email-driven phishing campaign using what’s called “adversary-in-the-middle” (AitM) techniques, as reported by The Hacker News. In plain English, this means the attacker sits invisibly between you and Microsoft when you log in. You type your username and password into what looks like a genuine Microsoft sign-in page, and behind the scenes the attacker’s system passes those details straight through to the real Microsoft 365 login – capturing your session in the process.
The clever (and nasty) part is that this technique can also intercept the session after multi-factor authentication (MFA) has been completed. So even if you’ve ticked the “we use MFA, we’re covered” box, this particular style of attack can still get through in some cases, because it’s stealing the active session rather than just the password.
Once inside, the attackers don’t necessarily act straight away. Instead, they use residential proxy networks to make their access look like normal, everyday login activity from a regular home internet connection – rather than something obviously suspicious like a login from overseas. This helps them stay hidden while they quietly search through mailboxes for anyone involved in financial workflows: bookkeepers, office managers, accounts payable staff, and business owners who approve payments.
Large enterprises typically have dedicated security teams monitoring login activity around the clock. Small and medium businesses in regional Victoria generally don’t – and that’s exactly why this type of attack is so effective against smaller operators. A local trades business, professional services firm, or retailer with one person handling the books is a much easier target than a company with a 24/7 security operations centre watching every login.
Once the attackers understand your business’s financial workflow, they can either sit and read invoices and payment approvals to time a fraudulent request perfectly, or they can send emails from your own compromised account to suppliers, clients, or your bookkeeper asking for a bank detail change or an “urgent” payment. Because it’s genuinely coming from your real email account, it often bypasses the usual red flags people are trained to look for.
Multi-factor authentication is still one of the single best things a small business can do to protect itself, and we’re not suggesting you skip it. But this campaign is a good reminder that not all MFA is equal. Basic MFA methods – like a code sent via SMS or a simple “approve” push notification – can be intercepted or tricked by AitM techniques because the attacker is capturing the whole session, codes and all.
Phishing-resistant MFA methods, such as physical security keys (FIDO2) or number-matching authenticator apps with additional context, are much harder for this kind of attack to defeat, because there’s no code or approval prompt to intercept in the same way.
If you notice unusual sign-in activity, unexpected mailbox rules, or a supplier says they received a strange payment request from your business, act immediately. Change the affected password, revoke active sessions (this forces the attacker’s stolen session to be logged out), review and remove any suspicious mailbox rules, and check sent items for anything you didn’t send. It’s also worth notifying anyone you regularly invoice or pay, in case fraudulent emails have already gone out under your name.
This campaign is a timely reminder that cybercriminals are increasingly patient and methodical. Rather than a smash-and-grab, they’re happy to sit inside a mailbox for days or weeks, learning how a business operates before striking at exactly the right moment – usually around payroll runs, supplier payments, or invoice due dates. For regional businesses that pride themselves on strong relationships with suppliers and clients, this kind of impersonation can be just as damaging to trust and reputation as it is financially.
The good news is that the defences here are well within reach for a small business – most of them are built into Microsoft 365 already, they just need to be switched on and configured properly. Taking an hour to review your MFA settings, mailbox rules, and sign-in logs now is a lot cheaper than dealing with a fraudulent payment or a damaged supplier relationship later.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804