Microsoft Phishing Attack Can Bypass MFA: How Indian Users Can Stay Safe
Multi-factor authentication (MFA) remains an important security layer, but it cannot stop every phishing attack. A recent campaign shows how attackers can steal Microsoft login details and session cookies even after a victim completes MFA.
How the Microsoft Phishing Attack Works
According to Proofpoint research reported by The Hacker News, the group tracked as TA419 targeted AI policy experts at U.S. think tanks, universities and law firms. Proofpoint assesses the group as likely China-aligned, although this attribution is not proven.
The campaign uses carefully crafted emails to build trust before sending victims through shortened links, redirects and CAPTCHA checks. The final page uses a fake Microsoft sign-in window displayed inside the webpage.
Behind this fake login, an adversary-in-the-middle (AitM) setup relays the authentication process to the genuine Microsoft service. This can allow attackers to capture the victim's password and session cookie. Because the session has already been authenticated, the stolen cookie can potentially allow access without asking for the MFA code again.
Why Indian Microsoft 365 Users Should Care
Although the reported victims were in the U.S., the technique can affect Microsoft 365 and Outlook users anywhere, including Indian businesses, IT companies, professionals and SMEs.
Attackers may use similar approaches for email compromise, data theft or invoice-related fraud. A polite message asking someone to review a document or provide feedback can be enough to start the attack.


How to Reduce the Risk
- Avoid signing in through links received by email or chat. Open the official service directly.
- Be cautious of login screens appearing inside another webpage and check the browser's address bar.
- Verify unexpected document or review requests through another communication channel.
- Use phishing-resistant authentication, such as passkeys or security keys, where available.
- If an account may be compromised, review recent activity, sign out existing sessions and change the password.
- Encourage employees to report suspicious messages quickly.
MFA should remain enabled, but businesses should not treat it as a complete defence against modern phishing. Strong authentication methods combined with careful user behaviour can provide better protection.
Phishing often begins with a malicious link or website. Net Protector Cyber Security offers security solutions including anti-phishing protection in Total Security and Corporate Web Control for businesses. These protections can complement, but do not replace, strong authentication and user awareness.