The Compliance Trap: How a 13,000-Org Phishing Wave Bypasses MFA via AiTM Proxying
ID: 4b3c4849-96a7-5fd8-b3c0-8c45f471d392
STIX ID: report--4b3c4849-96a7-5fd8-b3c0-8c45f471d392
Feed Name: securityonline.info
Microsoft Defender reported a large, highly sophisticated credential-theft campaign that targeted over 13,000 organizations across 26 countries between April 14–16, 2026, using code-of-conduct-themed phishing PDFs, CAPTCHA gating to evade automated analysis, and an Adversary-in-the-Middle (AiTM) proxy that intercepted live authentication tokens to bypass standard MFA; the campaign heavily targeted U.S. organizations in healthcare, financial services, professional services, and technology, and Microsoft recommends layered defenses including advanced anti-phishing, phishing-resistant MFA (FIDO/Windows Hello), and browser protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
