Hackers Exploit Outlook Accounts to Hijack MFA-Protected Microsoft 365 Sessions

Cybercriminals have developed a sophisticated method to compromise Microsoft Outlook accounts, enabling them to hijack Microsoft 365 sessions protected by multi-factor authentication (MFA). This technique, known as adversary-in-the-middle (AiTM) phishing, allows attackers to intercept and steal active session tokens, granting them unauthorized access to sensitive organizational data.

The campaign, which began in May 2026, targets universities, enterprises, and multinational institutions, including entities associated with the European Union and United Nations. Attackers initiate the breach by sending phishing emails that mimic legitimate business communications, such as requests for information, bid invitations, and shared project documents. These emails often originate from compromised internal addresses, making them appear trustworthy to recipients.

Upon clicking the embedded links, victims are directed through a series of deceptive steps, including fake download pages, CAPTCHA prompts, and cloned login portals that closely resemble official Microsoft 365 interfaces. This process is designed to feel authentic, leading users to unknowingly provide their login credentials and MFA codes directly to the attackers.

Once the attackers obtain these credentials, they establish a man-in-the-middle position between the user and the legitimate Microsoft 365 service. This allows them to intercept session cookies and tokens, effectively bypassing MFA protections. With these tokens, attackers can access email accounts, sensitive documents, and other critical resources without needing the user’s password or additional authentication.

Security researchers have observed that after compromising an initial Outlook account, attackers leverage it to send further phishing emails to internal and external contacts, exponentially increasing their reach and the potential for additional breaches. This method not only facilitates the spread of the attack but also exploits the inherent trust within organizational communication channels.

To mitigate the risks associated with such sophisticated phishing campaigns, organizations are advised to implement several security measures:

  • Enhanced Email Filtering: Deploy advanced email filtering solutions capable of detecting and blocking phishing attempts, even those originating from internal accounts.
  • User Education: Conduct regular training sessions to educate employees about the latest phishing tactics and the importance of scrutinizing unexpected emails, even from known contacts.
  • Behavioral Analytics: Utilize security tools that monitor user behavior for anomalies, such as unusual login locations or times, which may indicate a compromised account.
  • Zero Trust Architecture: Adopt a zero trust security model that requires continuous verification of user identity and device security posture, regardless of location or network.

As cyber threats continue to evolve, it is crucial for organizations to stay vigilant and proactive in their security practices. Regularly updating security protocols, educating employees, and leveraging advanced detection technologies are essential steps in defending against sophisticated attacks like AiTM phishing.

In conclusion, the exploitation of Outlook accounts to hijack MFA-protected Microsoft 365 sessions underscores the need for a multi-layered security approach. Organizations must not only implement robust technical defenses but also foster a culture of security awareness to effectively combat these evolving threats.