The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Microsoft reported that a phishing campaign moved from a compromised trusted vendor into banking and financial-services organizations, then used stolen authenticated sessions to support more phishing and business email compromise (BEC). The June 2023 report does not name the banks or other individual victims. Its central lesson: multifactor authentication (MFA) can be bypassed in practice when an attacker steals a session after a user completes sign-in.
How did the campaign move from a vendor to financial firms?
Microsoft Threat Intelligence described a multi-stage campaign attributed to Storm-1167, which operated the AiTM phishing kit. The activity began with a compromised vendor relationship: attackers used the trusted connection to reach another organization, rather than relying only on unsolicited messages to strangers. Microsoft’s June 8, 2023 account traces the sequence into banking and financial-services organizations, but does not identify the victims.
- Steal an authenticated session. A targeted user was sent to an attacker-controlled page imitating the sign-in page for the real service. In this case, the page used an indirect-proxy flow: it captured the user’s credentials and MFA response, then passed authentication through to the legitimate service.
- Replay the session. Once sign-in succeeded, the attacker obtained a session token and could replay it to act as the authenticated user. The method is distinct from a classic reverse-proxy AiTM attack, in which the attacker proxies traffic between the user and the legitimate service.
- Change authentication methods. Microsoft said the affected MFA policies were not configured according to security best practices. Attackers used that weakness to modify authentication methods without facing another MFA challenge.
- Use the compromised organization to reach more people. The attackers sent more than 16,000 emails to the target’s contacts in a second-stage phishing campaign, according to Microsoft Threat Intelligence’s 2023 report. Further phishing and BEC activity then extended across business partners.
That sequence explains why a vendor compromise can become a financial-sector problem: a trusted account can make malicious messages appear credible, and each compromised organization can provide access to another set of business relationships. Microsoft characterized the intent as financial fraud, but its report does not establish that a payment was successfully diverted in this particular 2023 campaign.
What does AiTM phishing do that ordinary password theft does not?
Ordinary credential theft gives an attacker a password to try. AiTM phishing can capture the result of a successful sign-in as well: the authenticated session. A session cookie or token tells a service that the user has already passed authentication, including MFA, so replaying it can let an attacker act without immediately asking for the password or MFA code again.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
This does not mean MFA itself is broken. Microsoft’s 2022 explanation of cookie theft says the attacker targets session material after authentication. A one-time code may be valid and correctly entered, but it does not stop an attacker from stealing the resulting session through a convincing phishing flow. Phishing-resistant authentication can reduce exposure to credential-phishing sites, while session revocation is needed if a session has already been stolen.
How can an email account turn into attempted payment fraud?
Once inside a mailbox, an attacker can exploit existing business conversations rather than inventing a new story. Microsoft’s separate 2022 reporting on cookie theft and BEC described attackers searching finance-related mail, hijacking payment threads, hiding replies with inbox rules, and attempting to redirect payments. In that separate campaign, Microsoft observed follow-on payment fraud beginning as little as five minutes after credential and session theft. That timing and those tactics are an example from a different campaign, not a finding about the 2023 banking-sector activity.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
The practical risk for a business or its customers is that a fraudulent instruction may arrive in a familiar thread or from an account the recipient already trusts. Treat a change to bank details or payment instructions as a separate verification event: confirm it using a known phone number or another independently established channel, not contact details supplied in the changed message.
Which defenses address phishing, stolen sessions, and mailbox abuse?
No single control covers the full sequence. Authentication hardening aims to prevent the initial compromise; access policies can restrict where or how a session is used; and monitoring helps uncover suspicious sign-ins and mailbox actions. These measures reduce risk but do not replace incident response when an account or session is already compromised.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Defense | What it helps prevent or reveal | Important limitation |
|---|---|---|
| Phishing-resistant authentication, such as FIDO v2.0 or certificate-based authentication | Reduces susceptibility to credential phishing by requiring an authentication method tied more securely to the legitimate service or credential. | It does not revoke an already stolen session. Microsoft recommended these methods in its 2022 guidance; specific hardware products or endorsements were not identified. |
| Conditional access, including compliant-device or trusted-IP requirements | Can restrict access based on conditions such as device compliance or network location, adding checks beyond possession of a password. | Effect depends on policy design and enforcement in the organization’s environment; it is not a guarantee that every stolen session will be blocked. |
| Advanced anti-phishing protection for email and web destinations | Can help detect or block deceptive messages and malicious sign-in destinations before a user submits credentials. | It is a preventive layer, not a substitute for revoking sessions or investigating activity after compromise. |
| Continuous monitoring of sign-ins and mailbox activity | Can surface anomalous sign-ins, suspicious inbox-rule changes, stolen-session use, or phishing sent from compromised accounts. | Detection depends on the tools, data, alert configuration, and response capacity available to the organization. Some Microsoft alerts require the relevant Microsoft security products. |
Microsoft’s recommendations for AiTM defense include phishing-resistant authentication, conditional access controls, anti-phishing protection, and continuous monitoring for suspicious sign-ins. In the 2025 Digital Defense Report, Microsoft also described BEC patterns including inbox-rule manipulation, unauthorized SharePoint access, internal phishing, thread hijacking, new MFA-method registration, and MFA tampering. The report’s January–June 2025 sector distribution put financial services at 7% of observed BEC activity; that figure is broad, later context, not a measure of this 2023 campaign.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should an organization do after suspected AiTM compromise?
A password reset alone is insufficient in the scenario Microsoft described: the attacker may still have a valid session or have altered authentication methods. Response needs to address identity, sessions, messages, and related mailbox activity.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Contain the affected accounts and campaign. Limit the compromised account’s ability to send more mail and investigate whether the phishing message reached other users or partner organizations.
- Revoke session cookies and tokens. Invalidate active sessions so a stolen session cannot simply continue to be replayed.
- Undo unauthorized authentication changes. Review registered MFA methods and remove or roll back attacker-added methods, then secure the user’s credentials and legitimate authentication methods.
- Remove campaign emails and examine related activity. Search for and remove malicious messages, then investigate anomalous sign-ins, suspicious inbox rules, mailbox changes, and phishing sent by compromised users.
- Check business conversations involving money. Review payment-related threads and independently verify any changed instructions before funds are sent.
Microsoft describes detections for stolen-session use, possible AiTM attempts, suspicious inbox manipulation, anomalous sign-ins, and phishing sent by compromised users. Availability of those product-specific detections depends on the Microsoft security products and configuration in use; organizations should also investigate with the telemetry available in their own environment.
How widespread are the figures Microsoft reported?
The campaign numbers should not be combined: they describe different observations, not a single tally of victims or losses.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- More than 16,000 emails: the second-stage campaign sent to the target’s contacts in the 2023 banking and financial-services case, as reported by Microsoft Threat Intelligence.
- More than 10,000 organizations: a separate AiTM campaign Microsoft said it had observed targeting organizations since September 2021, in its 2022 report. This is not the number of organizations affected in the 2023 campaign.
- 7% of observed BEC activity: the financial-services share in Microsoft’s January–June 2025 sector distribution, not a count or share of victims in either earlier campaign.
Microsoft Threat Intelligence summarized the broader risk in its 2023 report: “This attack shows the complexity of AiTM and BEC threats, which abuse trusted relationships between vendors, suppliers, and other partner organizations with the intent of financial fraud.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




