Back to Blog

Your payroll emails are being stolen via a hidden Microsoft 365 phishing trick – what you must do now

Your payroll emails are being stolen via a hidden Microsoft 365 phishing trick – what you must do now
August 10, 2026|David Velarde RoblesDavid Velarde Robles

A hidden phishing trick is stealing payroll emails from Microsoft 365 – act now

Phishing protection for small business is essential, especially if you rely on Microsoft 365 for payroll, HR or finance communications, because a new AitM phishing campaign could already be reading those messages.
If your payroll emails are being read by strangers, your cash flow and employee data are at risk. The good news is you can stop it with three simple security steps.

If you rely on Microsoft 365 for your payroll, HR or finance communications, a new phishing campaign could already be reading those messages without you knowing it. Attackers are hijacking Microsoft 365 accounts, slipping past basic security, and harvesting the very emails that contain salary details, bank account numbers and payment instructions. The result? Money can be redirected, invoices altered, or confidential employee data exposed.

The good news is that you don’t need to become a security expert to stop it. By tightening three key controls—multi‑factor authentication (MFA), email‑gateway filtering, and regular privileged‑account reviews—you can block the attackers and keep your payroll safe.

What the attackers are doing (in plain language)

The technique is called adversary‑in‑the‑middle (AitM) phishing. Think of it as a very convincing “man‑in‑the‑middle” trick, but instead of intercepting a phone call, the criminals intercept the login flow to Microsoft 365.

  1. A deceptive email – The victim receives a message that looks like a routine invitation (often a Google Meet link).
  2. A fake login page – Clicking the link takes the user to a page that looks exactly like Microsoft’s sign‑in screen.
  3. Credential capture – When the user enters their password and the MFA code (the extra code sent to their phone), the page silently forwards those details to the attackers.
  4. Silent takeover – Using the stolen credentials, the criminals log into the real Microsoft 365 account, often from a residential proxy that mimics a normal home internet connection.
  5. Targeted email harvesting – They then use Microsoft’s own Graph API (a tool that lets apps read mailbox contents) to pull any emails that mention payroll, HR or finance.

Because the sign‑ins appear to come from ordinary home IP addresses and even use legitimate‑looking browsers, many organisations’ existing security alerts miss the activity. The attackers keep the compromised sessions alive, refreshing them every eight hours, so they can continue to collect sensitive emails over days or weeks.

Why payroll and finance mailboxes are prime targets

Payroll and finance communications contain the “keys to the cash register” of any business:

  • Bank account numbers for salary deposits or vendor payments.
  • Invoice attachments that can be altered to redirect payments.
  • Salary‑change requests that look legitimate but can be forged.

If an attacker can read or modify these messages, they can reroute money to their own accounts, create fake vendors, or even blackmail the business with sensitive employee data. For a small business, a single successful theft can wipe out months of cash flow.

Phishing protection for small business: three steps you can implement today

1. Enforce MFA on every Microsoft 365 account

MFA adds an extra verification step—usually a code sent to a phone or generated by an authenticator app. Even if a password is stolen, the attacker still needs the second factor.

  • Set it as mandatory for all users, not just administrators.
  • Prefer authenticator apps over SMS, because text messages can be intercepted.
  • Regularly review MFA methods to ensure no legacy or less‑secure options remain.

2. Deploy an email‑gateway/anti‑phishing filter

An email gateway sits between the internet and your Microsoft 365 tenant, scanning inbound messages for known phishing patterns, malicious links and suspicious attachments.

  • Choose a solution that integrates with Microsoft 365 and can rewrite or block dangerous URLs before they reach users.
  • Enable real‑time link scanning so that even newly created malicious pages are caught.
  • Configure the gateway to quarantine messages that contain payroll‑related keywords from unknown senders, giving you a chance to review them.

3. Schedule regular privileged‑account reviews

Every few months, audit accounts with elevated permissions such as finance, HR or global admin. Remove any unnecessary access and flag sign‑ins from unfamiliar locations or devices.

FAQ

How do I know if my Microsoft 365 account was compromised?
Check the Microsoft 365 admin portal for sign‑in logs that show unfamiliar locations, devices or repeated failed MFA attempts. Unusual activity such as “mobile Safari on Windows” is a strong indicator of a fake login flow.

Is MFA enough on its own?
MFA dramatically reduces risk, but sophisticated AitM attacks can still capture the second factor if the user enters it on a fake page. Combining MFA with email‑gateway filtering and regular account reviews creates layered protection that is far harder to bypass.

Can I automate the privileged‑account reviews?
Yes. Many security tools (including Microsoft 365’s own compliance center) can generate scheduled reports of users with high‑privilege roles. You can set up a simple PowerShell script or use a third‑party monitoring service to email you the list each quarter.

Keep your payroll safe with IT Move NL

Protecting your business’s money shouldn’t feel like a full‑time job. Our Security & Protection service takes the three steps above and turns them into a managed solution:

  • MFA configuration for every user, with ongoing monitoring for suspicious attempts.
  • Advanced email‑gateway filtering that blocks phishing links before they land in inboxes.
  • Quarterly privileged‑account reviews performed by our security specialists, with a clear report and remediation plan.

We understand the pressure of running a small business—technology should work for you, not against you. Let us handle the security details so you can focus on growing your bakery, dental clinic, or logistics fleet without worrying about payroll emails being stolen.

Ready to secure your Microsoft 365 tenant? Get in touch today and we’ll set up a quick, no‑obligation assessment of your current protections.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch