← All articles

consultant

“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response

Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.

On May 4, 2026, Microsoft published an analysis of a multi‑stage phishing campaign spoofing an internal “code of conduct” to hijack Microsoft 365 sessions via an adversary‑in‑the‑middle (AiTM) kit. Aim: steal credentials and tokens in real time to bypass legacy MFA. Source: Microsoft Security Blog (05/04/2026).

Key facts

  • Vector: tailored emails announcing a “code of conduct review” with a supposedly personalized attachment.
  • Technique: AiTM proxy placed between user and Microsoft portals to capture credentials and cookies/tokens in real time.
  • Targets: Microsoft 365/Entra ID accounts; goals observed: mailbox takeover, SSO access, BEC scenarios.
  • IOCs: campaign infrastructure and sender addresses published by Microsoft under the “Indicators” section.

The campaign reflects a broader trend mixing vishing/AiTM with cloud session hijacking, with finance‑focused attacks linked to UNC6671/BlackFile in summer 2026 (ref. BleepingComputer, 08/06/2026).

Applicable legal framework

  • GDPR, Article 32 — security of processing: proportionate technical/organizational controls, including strong authentication and effectiveness testing. Phishing‑resistant MFA is today the state of the art for Internet‑exposed accounts. Text: EUR‑Lex — GDPR. For a concise compliance view, see our GDPR page.
  • NIS 2, Article 21 — cyber risk management covering IAM/MFA and communications security. Text: EUR‑Lex — NIS 2.
  • Incident notification (LU) — preliminary alert within 24 h to ILR via SERIMA, 72 h notification, and final report within one month. Refs: ILR, Luxembourg Government, and EU common templates (05/26/2026): European Commission. Local context is summarized on our NIS 2 Luxembourg page.

Technical solution: phishing‑resistant MFA (FIDO2/WebAuthn)

How it works

  • FIDO2/WebAuthn passkeys: key pair (private on device, public on service); signatures are bound to the legitimate origin — an AiTM proxy cannot replicate it.
  • Resistant factors: hardware security keys (USB/NFC), Secure Enclave/TPM, local biometrics; no reusable shared secret.
  • Conditional access: enforce FIDO2 for sensitive roles and admins; disable OTP/push for those scopes; require high MFA strength.
  • Session hardening: token binding, contextual re‑auth; monitor “MailItemsAccessed” and session anomalies.
  • Mail/DNS hygiene: strict DMARC/SPF/DKIM; real‑time URL filtering.

References: ISO/IEC 27001:2022 (A.5.17, A.8.2), NIST SP 800‑63B (AAL2/AAL3), CIS Controls (Control 6).

Tangible benefits

  • Against AiTM: origin checking plus password/OTP elimination neutralizes the transparent proxy.
  • Surface reduction: phase‑out of weak factors (SMS, push‑to‑approve) on exposed units.
  • Evidence: authentication logs (method, device, origin) demonstrate GDPR 32 adequacy and feed NIS 2 notifications.

How Luxgap delivers

  • Governance: authentication policies and critical role mapping; “standard MFA” vs “reinforced MFA” (mandatory FIDO2). Our DPO/CISO teams align GDPR/NIS 2. For detection at scale, see our 24/7 managed SOC.
  • 24/7 SOC: ingest Entra ID/Okta/M365 logs, correlate with Microsoft IOCs, detect AiTM (UA, IP, session), and run ILR (SERIMA) alert/notification playbooks.
  • Externalized DPO/CISO: validate legal bases, “MFA by design” for HR/finance, and rehearse 24 h / 72 h notifications. Learn more about the DPO mandate.

Typical timeline (6–8 weeks)

  1. Authentication methods and critical scope audit.
  2. FIDO2 pilot in a high‑risk department.
  3. Gradual migration of accounts and admins.
  4. Conditional access hardening.
  5. SIEM/SOC onboarding and AiTM scenarios.
  6. Table‑top exercise for ILR 24 h notification.

Customer case (EU/Luxembourg)

A NIS 2‑in‑scope fiduciary processing payroll data moved 220 finance/HR accounts and 35 admins to FIDO2 passkeys, blocking OTP/push for those roles. In 7 weeks: −93% malicious domain login attempts at the mail gateway; zero AiTM bypass across two targeted campaigns; and a ready GDPR 32/NIS 2 evidence pack (logs, policies, control matrix).

First steps

  • Inventory MFA methods per population; prioritize HR/finance/procurement and admins.
  • Enable “reinforced MFA” policies enforcing FIDO2 and disable OTP/push for sensitive roles.
  • Harden the email gateway (DMARC/SPF/DKIM, URL blocking) and add Microsoft‑published IOCs to block lists.
  • Monitor AiTM signals: residential IPs, abnormal refreshes, unusual “MailItemsAccessed”. Operational support is detailed in our 24/7 incident detection offering.
  • Test ILR notification via SERIMA; for local context, refer to NIS 2 Luxembourg and ILR.

Official sources

Need a quick assessment of your exposure and MFA posture? Get in touch.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →