Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted hundreds of organizations in the U.S., Canada, and Europe, making the credential theft and session hijacking effort broad enough to affect many enterprises at once.

Related Happenings

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign

Campaign
H score37 First: 04.08.2026 03:17 Last: 04.08.2026 03:17 Sources 1

About this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
H score34 First: 24.07.2026 20:50 Last: 24.07.2026 20:50 Sources 1

About this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

Timeline

  1. 07.08.2026 13:38 2 articles · 1h ago

    Email-driven AitM phishing campaign hijacks Microsoft 365 accounts

    Initial Disclosure

    An active email-driven adversary-in-the-middle phishing campaign is hijacking Microsoft 365 accounts to identify payroll and HR personnel and collect related mailbox data, with hundreds of organizations targeted across the U.S., Canada, and Europe. The activity uses residential proxies and proxied Microsoft authentication to blend malicious sign-ins into ordinary consumer traffic.

    Show sources