
TrendAI says a BEC attacker used a spear-phishing email to steal a Microsoft 365 session token, bypass MFA, and reroute vendor payments for 30 days before detection.
A business email compromise scheme used a stolen Microsoft 365 session token to reroute vendor payments for 30 days before detection, cybersecurity firm TrendAI said in an Aug. 14 blog post.
The attacker targeted a finance employee with a spear-phishing email that included the person's name, job title and organization. The email claimed to be about a denied PTO request and contained a button labeled "View Conflicting PTO Dates." Clicking it led to an Adversary-in-the-Middle phishing page that bypassed multifactor authentication and captured the victim's live session token, TrendAI said.
Once the token was in hand, the attacker set up three malicious inbox rules. Those rules auto-archived and marked as read incoming vendor and internal collection emails, hiding the fraud from the victim. Over the next month, the attacker impersonated vendors and directed the company's payments to bank accounts the attacker controlled, according to the post.
"The BEC campaign is another illustration of where the enterprise perimeter really sits today: trust and identity," TrendAI said. "By stealing a single authenticated session, the minds behind this campaign gained everything they needed to impersonate a finance user and redirect real money."
Business email compromise attacks have become more sophisticated in recent years. A December 2024 PYMNTS Intelligence report found that 83% of U.S. companies had been targeted by highly sophisticated cyberfraud, with BEC schemes making up the largest share. The report urged companies to adopt fraud prevention strategies, noting that "fraudsters continue to develop new tactics."
The TrendAI disclosure highlights how session token theft can bypass even strong authentication controls. The attacker did not need the victim's password or a second factor after the initial phishing capture. The 30-day concealment period gave the attacker time to redirect multiple payments before the company noticed the missing vendor invoices.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.