Aug 7
/
Latest News
AitM Phishing Campaign Hits Microsoft 365 Accounts as Swiss Government Confirms SharePoint Breach
Cybersecurity researchers are warning of a widespread email‑driven phishing campaign that uses adversary‑in‑the‑middle (AitM) techniques to hijack Microsoft 365 accounts and identify payroll and finance personnel. According to Arctic Wolf Labs, the attackers rely on residential proxies to disguise malicious sign‑ins as normal consumer traffic, refreshing compromised sessions every eight hours.
The campaign targets organizations across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe. It overlaps tactically with Payroll Pirate activity tracked by Microsoft as Storm‑2755, a financially motivated cluster known for rerouting salary payments through compromised employee accounts.
Arctic Wolf observed hundreds of organizations targeted last month through voicemail‑themed phishing emails that redirect victims through a six‑stage chain using trusted services such as Google, Google Ads, Google Meet, and Amazon S3. These redirects ultimately lead to AitM proxy pages that capture credentials and MFA codes while mimicking Microsoft’s OAuth flow.
The phishing infrastructure fingerprints visiting hosts using JavaScript, collecting browser, OS, screen dimensions, language, time zone, cookie support, WebGL vendor, and API availability. It also queries a geolocation API to store the victim’s country code, which attackers later use to select geographically matched residential proxies for follow‑up logins.
Once access is obtained, the attackers quietly maintain stolen sessions and collect emails from payroll, HR, finance, and administrative staff. Sign‑ins often originate from rotating residential proxies and report unusual browser/OS combinations, such as mobile Safari on Windows 10. Despite the automation, most intrusions show limited post‑compromise activity beyond reconnaissance and mailbox collection.
In a handful of cases, attackers created inbox rules to hide messages by moving them to Deleted Items and marking them as read. Arctic Wolf notes that selective manual intervention appears to complement centralized automation that handles session refresh and data collection.
Separately, Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT) confirmed a breach of its SharePoint servers after attackers exploited recently disclosed Microsoft vulnerabilities. BIT detected unusual activity on July 28 and blocked internet access to the platform while patching the flaws.
By July 31, investigators found that login credentials for around 200 user and technical accounts had been compromised. BIT believes the intrusion involved SharePoint vulnerabilities disclosed and fixed in Microsoft’s July Patch Tuesday updates, potentially including CVE‑2026‑56164 or CVE‑2026‑50522. Passwords for all affected accounts were reset immediately.
BIT says no confidential or sensitive personal data is permitted on the affected SharePoint platform, and there is currently no evidence of data leakage beyond stolen credentials. The agency reported the incident to national authorities as required and shared technical indicators with critical infrastructure operators.
No threat group has claimed responsibility for the attack.
The campaign targets organizations across healthcare, education, manufacturing, government, and professional services in the U.S., Canada, and Europe. It overlaps tactically with Payroll Pirate activity tracked by Microsoft as Storm‑2755, a financially motivated cluster known for rerouting salary payments through compromised employee accounts.
Arctic Wolf observed hundreds of organizations targeted last month through voicemail‑themed phishing emails that redirect victims through a six‑stage chain using trusted services such as Google, Google Ads, Google Meet, and Amazon S3. These redirects ultimately lead to AitM proxy pages that capture credentials and MFA codes while mimicking Microsoft’s OAuth flow.
The phishing infrastructure fingerprints visiting hosts using JavaScript, collecting browser, OS, screen dimensions, language, time zone, cookie support, WebGL vendor, and API availability. It also queries a geolocation API to store the victim’s country code, which attackers later use to select geographically matched residential proxies for follow‑up logins.
Once access is obtained, the attackers quietly maintain stolen sessions and collect emails from payroll, HR, finance, and administrative staff. Sign‑ins often originate from rotating residential proxies and report unusual browser/OS combinations, such as mobile Safari on Windows 10. Despite the automation, most intrusions show limited post‑compromise activity beyond reconnaissance and mailbox collection.
In a handful of cases, attackers created inbox rules to hide messages by moving them to Deleted Items and marking them as read. Arctic Wolf notes that selective manual intervention appears to complement centralized automation that handles session refresh and data collection.
Separately, Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT) confirmed a breach of its SharePoint servers after attackers exploited recently disclosed Microsoft vulnerabilities. BIT detected unusual activity on July 28 and blocked internet access to the platform while patching the flaws.
By July 31, investigators found that login credentials for around 200 user and technical accounts had been compromised. BIT believes the intrusion involved SharePoint vulnerabilities disclosed and fixed in Microsoft’s July Patch Tuesday updates, potentially including CVE‑2026‑56164 or CVE‑2026‑50522. Passwords for all affected accounts were reset immediately.
BIT says no confidential or sensitive personal data is permitted on the affected SharePoint platform, and there is currently no evidence of data leakage beyond stolen credentials. The agency reported the incident to national authorities as required and shared technical indicators with critical infrastructure operators.
No threat group has claimed responsibility for the attack.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.