Skip to content

Sam's News — email-security — 2026-08-11

Email Security

8 Widespread AitM Phishing Campaign Hijacks Microsoft 365 Accounts to Steal Payroll Data

Cybersecurity researchers have identified an active, large-scale phishing campaign using adversary-in-the-middle (AitM) techniques to compromise Microsoft 365 accounts across multiple sectors. The attackers use voicemail-themed emails and residential proxies to capture credentials and MFA codes, then harvest payroll and finance-related emails from compromised accounts.

  • Hundreds of organizations targeted across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe
  • Campaign uses six-stage redirection chain through Google, Google Meet, Google Ads, and Amazon S3 to bypass email filters
  • Attackers employ residential proxies to mask malicious sign-ins as ordinary consumer traffic and maintain compromised sessions every ~8 hours
  • Activity shares tactical overlaps with Microsoft-tracked Payroll Pirate (Storm-2755) and Storm-2657 threat clusters dating to early 2025
  • Phishing pages fingerprint victim browsers and systems, capturing OS, browser, timezone, and WebDriver status before redirecting to AitM infrastructure

Sources: The Hacker News AI Web Searched

Security

6.5 New phishing attack exploits SSL/TLS certificates to target premium brand customers via WhatsApp

Attackers are exploiting SSL/TLS certificate legitimacy to launch phishing campaigns targeting customers of high-value brands via WhatsApp.

Sources: CyberSecurityNews RSS