How One Phishing Email Let Attackers Bypass MFA and Redirect a Company’s Vendor Payments
An HR-themed phishing lure led a finance employee to a fake Microsoft 365 login that stole an authenticated session cookie, letting attackers bypass MFA entirely. Over the following month they used mailbox access to redirect real vendor payments to accounts they controlled.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.