A single click on an HR-themed email was all it took. No malware, no exploit kit, no endpoint compromise just a stolen browser session that let an attacker walk straight past multi-factor authentication and into a company’s Microsoft 365 environment.
According to TrendAI Vision One’s Managed Detection and Response (MDR) team, this “cloud-only” business email compromise (BEC) shows how thoroughly the modern attack surface has shifted from the endpoint to the identity layer.
The intrusion began with a spear-phishing email disguised as a “PTO Request Denied” notice, personalized with the finance employee’s name and title.
AiTM Phishing Attack Steals MFA Session Tokens
The message was sent through SendGrid from a legitimately authorized domain, allowing it to sail past SPF, DKIM, and DMARC checks a reminder that email authentication protocols verify the sending infrastructure, not the sender’s intent.
A friendly-From spoof made the message appear to come from internal HR. One click on the embedded button triggered a multi-hop redirect chain ending at a convincing fake Microsoft 365 login page.

This is the technical core of the case. Rather than defeating MFA outright, the attacker used an Adversary-in-the-Middle (AiTM) relay to sit invisibly between the victim and the real Microsoft login service.
When the user completed the MFA prompt, the attacker captured the resulting authenticated session token, effectively inheriting a “verified” identity without ever needing the password or a second factor again.
That stolen cookie was then replayed from commercial VPN infrastructure, including an M247 exit node, producing an “impossible travel” anomaly between Amsterdam and Los Angeles roughly one minute apart.
Once inside, the attacker planted three malicious inbox rules to auto-archive and mark as read incoming vendor collection notices and internal threads, quietly muting the alarms that would normally follow a missed payment. Mailbox audit logs later showed SoftDelete and HardDelete operations consistent with evidence destruction.
The fraud unfolded in two overlapping tracks of impersonation. In Phase 1, the attacker posed as a vendor’s accounts-payable contact from a free webmail account, patiently building credibility over 11 email exchanges across three weeks before submitting fraudulent ACH banking details.
In Phase 2, the attacker escalated by spoofing a senior AP colleague from a look-alike domain, pressuring staff to push through fraudulent bank-detail changes for three different vendors within days.
Host forensics found no infostealers, no remote access tools, and no lateral movement because none existed. Every stage played out against Exchange Online, SharePoint, and Entra ID sign-in logs.

MDR analysts pieced the case together by correlating single-factor sign-ins marked “MFA previously satisfied,” unbound token protection, and inbox-rule creation from foreign IPs.
The report recommends three defenses: unify endpoint, email, and identity telemetry to catch cross-domain attacks like this one; enable Entra ID Conditional Access token protection to bind sessions to specific devices; and mandate out-of-band, call-back verification for any vendor banking change a control that would have stopped the fraud even after the account was fully compromised.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.