Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments

A single phishing email was enough to give attackers access to a finance employee’s Microsoft 365 account and redirect vendor payments. The incident shows how criminals can bypass multi-factor authentication without installing malware or breaking into a company device. The attackers used a targeted HR-themed message that claimed a paid-time-off request had been denied. The […]

This article has been indexed from Cyber Security News

Read the original article: