Most businesses assume that turning on Multi-Factor Authentication (MFA) on Microsoft 365 keeps their accounts safe from takeover. MFA is a crucial layer of cybersecurity — but it’s no longer the whole story. Here’s a real attack on one of our clients that MFA alone could not have stopped, and how it was contained in under 15 minutes.
The threat: session token hijacking
Masking their location behind an anonymised VPN, the attacker began scanning the mailbox for invoice threads, supplier names and payment relationships. Within seconds they created a hidden inbox rule that silently redirected all invoice-related emails to the RSS Feeds folder — a place almost nobody checks. The plan: intercept payment emails, swap in fraudulent bank details, and wait for money to move. This is Business Email Compromise, one of the most financially damaging attacks facing UK businesses today.
The response: caught in 14 minutes
At 08:38, Huntress Managed ITDR detected the malicious inbox rule the moment it was created and raised a critical alert. A human security analyst — not just an automated system — reviewed it, confirmed the threat, and acted: all active sessions were revoked (ejecting the attacker), the compromised account was disabled, and the malicious rule was removed. By 08:52 the threat was contained.
Why ITDR is now essential
MFA still matters — but session hijacking exists specifically to get around it. Once an attacker holds a valid session token, traditional controls won’t see them coming. Identity Threat Detection and Response (ITDR) fills that gap, monitoring your Microsoft 365 continuously for the signals that matter — suspicious inbox rules, anomalous sessions, VPN-masked logins and OAuth abuse — with a real analyst investigating the moment something fires.
Talk to us about protecting your Microsoft 365
Frequently Asked Questions
Yes. Attacks such as Adversary-in-the-Middle steal an already-authenticated session token, letting an attacker in with MFA already satisfied. MFA is essential but not sufficient on its own — which is why session and identity monitoring (ITDR) matters.
An attack where a criminal gets into a business mailbox and manipulates payment communications — often by hiding inbox rules and swapping bank details on invoices — to divert payments. It is one of the costliest attacks facing UK businesses.
ITDR continuously monitors your Microsoft 365 identities and sessions for signs of compromise — suspicious inbox rules, anomalous logins, session hijacking — with a security analyst investigating in real time. It catches what MFA alone cannot.

