“Code of conduct” AiTM campaign against Microsoft 365: a GDPR-aligned response
Microsoft detailed an AiTM phishing campaign against Microsoft 365 and published IOCs. Here is how phishing-resistant MFA (FIDO2/WebAuthn) operationalizes GDPR Article 32 and reduces operational risk.
On May 4, 2026, Microsoft published an analysis of a multi‑stage phishing campaign spoofing an internal “code of conduct” to hijack Microsoft 365 sessions via an adversary‑in‑the‑middle (AiTM) kit. Aim: steal credentials and tokens in real time to bypass legacy MFA. Source: Microsoft Security Blog (05/04/2026).
Key facts
- Vector: tailored emails announcing a “code of conduct review” with a supposedly personalized attachment.
- Technique: AiTM proxy placed between user and Microsoft portals to capture credentials and cookies/tokens in real time.
- Targets: Microsoft 365/Entra ID accounts; goals observed: mailbox takeover, SSO access, BEC scenarios.
- IOCs: campaign infrastructure and sender addresses published by Microsoft under the “Indicators” section.
The campaign reflects a broader trend mixing vishing/AiTM with cloud session hijacking, with finance‑focused attacks linked to UNC6671/BlackFile in summer 2026 (ref. BleepingComputer, 08/06/2026).
Applicable legal framework
- GDPR, Article 32 — security of processing: proportionate technical/organizational controls, including strong authentication and effectiveness testing. Phishing‑resistant MFA is today the state of the art for Internet‑exposed accounts. Text: EUR‑Lex — GDPR. For a concise compliance view, see our GDPR page.
- NIS 2, Article 21 — cyber risk management covering IAM/MFA and communications security. Text: EUR‑Lex — NIS 2.
- Incident notification (LU) — preliminary alert within 24 h to ILR via SERIMA, 72 h notification, and final report within one month. Refs: ILR, Luxembourg Government, and EU common templates (05/26/2026): European Commission. Local context is summarized on our NIS 2 Luxembourg page.
Technical solution: phishing‑resistant MFA (FIDO2/WebAuthn)
How it works
- FIDO2/WebAuthn passkeys: key pair (private on device, public on service); signatures are bound to the legitimate origin — an AiTM proxy cannot replicate it.
- Resistant factors: hardware security keys (USB/NFC), Secure Enclave/TPM, local biometrics; no reusable shared secret.
- Conditional access: enforce FIDO2 for sensitive roles and admins; disable OTP/push for those scopes; require high MFA strength.
- Session hardening: token binding, contextual re‑auth; monitor “MailItemsAccessed” and session anomalies.
- Mail/DNS hygiene: strict DMARC/SPF/DKIM; real‑time URL filtering.
References: ISO/IEC 27001:2022 (A.5.17, A.8.2), NIST SP 800‑63B (AAL2/AAL3), CIS Controls (Control 6).
Tangible benefits
- Against AiTM: origin checking plus password/OTP elimination neutralizes the transparent proxy.
- Surface reduction: phase‑out of weak factors (SMS, push‑to‑approve) on exposed units.
- Evidence: authentication logs (method, device, origin) demonstrate GDPR 32 adequacy and feed NIS 2 notifications.
How Luxgap delivers
- Governance: authentication policies and critical role mapping; “standard MFA” vs “reinforced MFA” (mandatory FIDO2). Our DPO/CISO teams align GDPR/NIS 2. For detection at scale, see our 24/7 managed SOC.
- 24/7 SOC: ingest Entra ID/Okta/M365 logs, correlate with Microsoft IOCs, detect AiTM (UA, IP, session), and run ILR (SERIMA) alert/notification playbooks.
- Externalized DPO/CISO: validate legal bases, “MFA by design” for HR/finance, and rehearse 24 h / 72 h notifications. Learn more about the DPO mandate.
Typical timeline (6–8 weeks)
- Authentication methods and critical scope audit.
- FIDO2 pilot in a high‑risk department.
- Gradual migration of accounts and admins.
- Conditional access hardening.
- SIEM/SOC onboarding and AiTM scenarios.
- Table‑top exercise for ILR 24 h notification.
Customer case (EU/Luxembourg)
A NIS 2‑in‑scope fiduciary processing payroll data moved 220 finance/HR accounts and 35 admins to FIDO2 passkeys, blocking OTP/push for those roles. In 7 weeks: −93% malicious domain login attempts at the mail gateway; zero AiTM bypass across two targeted campaigns; and a ready GDPR 32/NIS 2 evidence pack (logs, policies, control matrix).
First steps
- Inventory MFA methods per population; prioritize HR/finance/procurement and admins.
- Enable “reinforced MFA” policies enforcing FIDO2 and disable OTP/push for sensitive roles.
- Harden the email gateway (DMARC/SPF/DKIM, URL blocking) and add Microsoft‑published IOCs to block lists.
- Monitor AiTM signals: residential IPs, abnormal refreshes, unusual “MailItemsAccessed”. Operational support is detailed in our 24/7 incident detection offering.
- Test ILR notification via SERIMA; for local context, refer to NIS 2 Luxembourg and ILR.
Official sources
- “Code of conduct” AiTM campaign and IOCs: Microsoft Security Blog (05/04/2026)
- Vishing/AiTM trends in finance (summer 2026): BleepingComputer (08/06/2026)
- GDPR — Article 32 security of processing: EUR‑Lex
- NIS 2 — Article 21 cyber risk management measures: EUR‑Lex
- 24 h / 72 h / 1 month notification — Luxembourg (SERIMA/ILR): ILR and Luxembourg Government
- Common EU reporting templates (05/26/2026): European Commission
Need a quick assessment of your exposure and MFA posture? Get in touch.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →