CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Microsoft 365 AitM Phishing Campaign Hijacks Accounts to Steal Payroll and Finance Emails

August 7, 2026

Cybersecurity researchers at Arctic Wolf Labs have uncovered a widespread email-driven phishing campaign that uses adversary-in-the-middle (AitM) techniques to compromise Microsoft 365 accounts, specifically targeting personnel involved in financial workflows. The campaign, active since at least July 2026, has impacted organizations across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe.

The attack chain begins with voicemail-themed phishing emails that lure victims through a six-stage redirection chain using legitimate services like Google Meet, Google Ads, and Amazon S3 to bypass reputation filters. The final stage presents a proxy page that captures credentials and multi-factor authentication (MFA) codes while the victim interacts with the legitimate Microsoft authentication flow.

Once access is obtained, the attackers use residential proxies to disguise malicious sign-ins as ordinary consumer traffic, maintaining sessions at approximately eight-hour intervals. They leverage the Microsoft Graph API to enumerate users in payroll, HR, finance, and administrative roles, then collect emails related to payroll, invoices, payments, and banking. The campaign shares tactical overlaps with the “Payroll Pirate” attacks tracked by Microsoft as Storm-2755, and related activity has been documented since early 2025 under Storm-2657.

Arctic Wolf observed hundreds of organizations targeted in the last month, with successful intrusions across a broad range of environments. The attackers avoid common BEC behaviors like inbox rule creation or credential modification, limiting early detection opportunities. However, in a few cases, hands-on-keyboard activity was used to create inbox rules that moved messages to Deleted Items. The use of rotating residential proxies and geolocation matching makes the campaign harder to trace back to the initial phishing event.

CVEs: CVE-2026-50522

Attack groups: Storm-2755, Storm-2657

Companies: Arctic Wolf Labs, Microsoft

Products: Microsoft 365, Microsoft Graph API