Adversary‑in‑the‑Middle Phishing Campaign Hijacks Microsoft 365 Accounts to Harvest Payroll and Finance Emails
What Happened — Researchers observed a large‑scale email‑driven phishing operation that uses adversary‑in‑the‑middle (AitM) techniques to compromise Microsoft 365 accounts. The attackers route sign‑ins through residential proxies, making the activity appear as normal consumer traffic, and then harvest emails from users involved in payroll and finance workflows.
Why It Matters for Compliance & Audit Readiness
- Credential‑based attacks directly test the effectiveness of SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) controls.
- Continuous evidence of phishing detection, MFA enforcement, and security‑awareness training is essential to demonstrate a defensible audit trail.
- The campaign highlights the need for real‑time monitoring of privileged account activity, a core requirement for maintaining a trustworthy SOC 2 posture.
Who Is Affected – Organizations that rely on Microsoft 365 for finance, payroll, or other sensitive business processes – notably firms in financial services, professional services, and any enterprise using cloud productivity suites.
Recommended Actions
- Verify MFA is enforced for all Microsoft 365 users, especially privileged and finance‑related accounts.
- Review sign‑in logs for anomalous locations or proxy usage and implement conditional access policies.
- Conduct targeted security‑awareness training that covers AitM phishing tactics and how to verify email authenticity.
- Map these activities to SOC 2 CC6.1/CC6.2 controls and capture evidence for audit readiness.
Source: The Hacker News
Technical Notes – The attack leverages residential proxy networks to mask malicious sign‑ins, bypassing basic IP‑based detection. No specific CVE is involved; the vector is social engineering (phishing) combined with credential reuse. The data targeted includes payroll and finance email content, which may contain personally identifiable information (PII) and financial records.