Mark RadarMARK RADAR
About
EN
Sign in
Event File FINTECH Phishing

Hackers Hijack Microsoft 365 Tokens to Steal Vendor Payments

1 reports · First detected 2026-08-21 · Last active 2026-08-21

Business email compromise typically relies on impersonating executives or suppliers to persuade finance staff to redirect legitimate payments. The newly disclosed campaign adds a more sophisticated element: attackers seize authenticated Microsoft 365 session tokens, allowing them to operate inside a victim’s mailbox even when multifactor authentication is enabled. That combination puts both corporate communications and established vendor-payment processes at risk because fraudulent instructions can appear within trusted email threads.

Security researchers said the attackers first sent phishing emails to finance personnel and then hijacked Microsoft 365 session tokens. Once inside, they created malicious inbox rules to conceal messages and security warnings, impersonated vendors and altered payment instructions so company funds would be routed to accounts they controlled. The report did not identify the affected organizations or attackers, and no specific incident date or stolen amount was disclosed.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)