When MFA Isn’t Enough: How We Stopped a Microsoft 365 Attack in 14 Minutes

Most businesses assume that turning on Multi-Factor Authentication (MFA) on Microsoft 365 keeps their accounts safe from takeover. MFA is a crucial layer of cybersecurity — but it’s no longer the whole story. Here’s a real attack on one of our clients that MFA alone could not have stopped, and how it was contained in under 15 minutes.

The threat: session token hijacking

The attacker didn’t steal a password or guess an MFA code. They used a technique called Adversary-in-the-Middle (AiTM): intercepting an already-authenticated session to steal the user’s session token. With that token they could access the Microsoft 365 account as the legitimate user — with MFA already satisfied. To the system, nothing looked wrong.

Masking their location behind an anonymised VPN, the attacker began scanning the mailbox for invoice threads, supplier names and payment relationships. Within seconds they created a hidden inbox rule that silently redirected all invoice-related emails to the RSS Feeds folder — a place almost nobody checks. The plan: intercept payment emails, swap in fraudulent bank details, and wait for money to move. This is Business Email Compromise, one of the most financially damaging attacks facing UK businesses today.

The response: caught in 14 minutes

At 08:38, Huntress Managed ITDR detected the malicious inbox rule the moment it was created and raised a critical alert. A human security analyst — not just an automated system — reviewed it, confirmed the threat, and acted: all active sessions were revoked (ejecting the attacker), the compromised account was disabled, and the malicious rule was removed. By 08:52 the threat was contained.

Our team then completed full remediation: credential rotation, an MFA device audit, a conditional-access policy review, and a complete activity audit of the affected account. The outcome: no data was exfiltrated, and no fraudulent payment was made.

Why ITDR is now essential

MFA still matters — but session hijacking exists specifically to get around it. Once an attacker holds a valid session token, traditional controls won’t see them coming. Identity Threat Detection and Response (ITDR) fills that gap, monitoring your Microsoft 365 continuously for the signals that matter — suspicious inbox rules, anomalous sessions, VPN-masked logins and OAuth abuse — with a real analyst investigating the moment something fires.

For most businesses, the honest answer to ‘would you know if someone was inside your email right now?’ is no. ITDR changes that.

Talk to us about protecting your Microsoft 365

We’ll walk you through how Huntress Managed ITDR protects your Microsoft 365 environment and whether it’s the right fit for you — at competitive rates. Call 01923 228820 or get in touch.

Frequently Asked Questions

Can Multi-Factor Authentication (MFA) be bypassed?

Yes. Attacks such as Adversary-in-the-Middle steal an already-authenticated session token, letting an attacker in with MFA already satisfied. MFA is essential but not sufficient on its own — which is why session and identity monitoring (ITDR) matters.

What is Business Email Compromise (BEC)?

An attack where a criminal gets into a business mailbox and manipulates payment communications — often by hiding inbox rules and swapping bank details on invoices — to divert payments. It is one of the costliest attacks facing UK businesses.

What is ITDR (Identity Threat Detection and Response)?

ITDR continuously monitors your Microsoft 365 identities and sessions for signs of compromise — suspicious inbox rules, anomalous logins, session hijacking — with a security analyst investigating in real time. It catches what MFA alone cannot.

Share This Post

More To Explore