Hackers Hijack Microsoft 365 Tokens to Steal Vendor Payments
Business email compromise typically relies on impersonating executives or suppliers to persuade finance staff to redirect legitimate payments. The newly disclosed campaign adds a more sophisticated element: attackers seize authenticated Microsoft 365 session tokens, allowing them to operate inside a victim’s mailbox even when multifactor authentication is enabled. That combination puts both corporate communications and established vendor-payment processes at risk because fraudulent instructions can appear within trusted email threads.
Security researchers said the attackers first sent phishing emails to finance personnel and then hijacked Microsoft 365 session tokens. Once inside, they created malicious inbox rules to conceal messages and security warnings, impersonated vendors and altered payment instructions so company funds would be routed to accounts they controlled. The report did not identify the affected organizations or attackers, and no specific incident date or stolen amount was disclosed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →