What Happened
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
Why It Matters
The report describes an active email-driven adversary-in-the-middle phishing campaign that targets Microsoft 365 accounts, captures credentials and MFA codes, and focuses on users involved in payroll and finance workflows. It also says the attackers use trusted services and residential proxies to make malicious sign-ins look like ordinary traffic. RealGround analysis: this is relevant to fintech AI risk because compromised finance-related mailboxes can expose payment instructions, approvals, and sensitive business communications, increasing the likelihood of fraud and business email compromise.
RealGround Analysis
This signal maps to fintech AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijacks.html
