Authored by: Bryan Lachapelle, President & CEO
Most of us know what a phishing attack looks like. Someone clicks a bad link, opens a malicious attachment, or enters a password somewhere they shouldn’t. But what if everything looks normal?
That’s what makes an Adversary-in-the-Middle (AiTM) attack particularly concerning. Instead of simply trying to steal your password, the attacker gets between you and the legitimate website or service you’re trying to access. From there, they may be able to intercept your login information and even hijack an authenticated session - sometimes when multi-factor authentication (MFA) is turned on.
For businesses using Microsoft 365, cloud applications, and remote access every day, it’s an attack worth understanding.
What Is an Adversary-in-the-Middle Attack?
Think about the last time you logged into Microsoft 365. Normally, you enter your username and password, complete your MFA prompt, and get to work. With an AiTM attack, you may be sent to a convincing fake login page controlled by a cybercriminal instead. You enter your information, and the attacker passes it along to the legitimate website. Your MFA request can be passed along too.
From your perspective, you’ve simply logged in. Behind the scenes, the attacker may be collecting the information they need to take over your authenticated session. That’s the scary part: you may not immediately realize anything went wrong.
But I Have MFA. Doesn’t That Protect Me?
MFA is still an important part of protecting your business, and we absolutely recommend using it. But MFA isn’t a magic shield against every type of cyberattack. In an AiTM attack, the cybercriminal may be after something called a session token. Think of that token like a temporary digital pass. Once you’ve successfully proven who you are, the website uses the token to remember that you’re already logged in.
If an attacker manages to steal that token, they may be able to hijack your authenticated session without entering your password or completing the same MFA challenge again. That doesn’t mean MFA isn’t working or isn’t worth having. It means MFA should be one layer of your cybersecurity strategy - not the whole strategy.
What Happens If an Attacker Gets In?
Unfortunately, a compromised business account can create problems well beyond someone reading your email.
Depending on the account and its permissions, an attacker could potentially:
- Access sensitive business information
- Read or steal emails and files
- Send phishing emails from a real employee account
- Target your clients, vendors, or other employees
- Change email rules to help hide their activity
- Attempt fraudulent payment or banking requests
- Use the account to try to gain further access to your organization
And because those emails are coming from a legitimate account, they can be much harder to spot. Imagine receiving a payment request from a vendor or co-worker you already know and trust. You’re much more likely to take it seriously than a message from a random email address. That trust is exactly what cybercriminals can try to take advantage of.
How Do These Attacks Start?
Often, it’s the same place many cyberattacks begin: phishing. An employee receives an email asking them to review a document, open a shared file, sign into an account, or deal with an urgent issue. They click the link and arrive at a login page that looks completely legitimate. The colours look right, the logo is there, the sign-in process feels familiar. And that’s why the old advice to simply “watch for spelling mistakes” isn’t enough anymore.
Modern phishing attempts can be incredibly convincing, which makes employee awareness and strong technical safeguards even more important.
What Can Your Business Do About It?
There isn’t one cybersecurity product you can turn on and forget about. Good security comes from having multiple layers working together.
Start with MFA: It remains an important protection, but businesses should also consider phishing-resistant authentication methods where appropriate.
Watch for unusual activity: Suspicious login locations, unfamiliar devices, and unusual account behaviour can all be signs that something isn’t right.
Protect more than the login screen: Email security, endpoint protection, access controls, employee cybersecurity training, and ongoing monitoring all have a role to play.
And don’t forget about what happens after someone realizes they may have made a mistake. If an employee enters their credentials on a suspicious website, do they know exactly who to call and what to do next? Having that response plan in place matters. The faster your team can act, the better chance you have of limiting what an attacker can access.
MFA Is Important, But It’s Not the Finish Line
If you’ve already enabled MFA, that’s a great step. Just don’t stop there. Cybersecurity threats continue to change, and attackers continue looking for ways around the protections businesses have put in place. AiTM attacks are a good reminder that cybersecurity isn’t something you check off your list once and forget about. Your business needs layers of protection that can help prevent an attack, spot suspicious activity, and respond quickly when something goes wrong.
Not sure whether your Microsoft 365 environment and current cybersecurity protections are ready for modern phishing and account takeover attempts? Give us a call! We can help you take a closer look at where your risks are and determine which additional protections make sense for your business.
Niagara: 905-228-4809
Barrie: 705-885-0993
