Blog

Incident Report: Phishing Attack

Detected, disrupted & automatically remediated in 6 minutes during an Adversary-in-the-Middle phishing incident.

A sophisticated phishing attack targeting an employee was detected, disrupted and automatically contained within six minutes.

The attacker captured the user’s password, intercepted an MFA approval and gained access to the Microsoft 365 account. Microsoft Defender and Entra responded automatically by invalidating active sessions, terminating the attacker’s access and forcing the account into remediation.

This incident demonstrates the value of having the right security controls in place. While phishing attacks continue to become more convincing, automated detection and response can prevent a compromised account from becoming a broader business incident.

Executive Summary

On 17 June 2026, a sophisticated phishing attack targeting an employee was automatically detected, disrupted, and remediated within 6 minutes. This was the first real-world test of the recently deployed Microsoft Defender suite, and the platform performed exactly as designed.

Background

The client organisation is part of the scope of the Microsoft Defender suite deployment scheduled for the week of 8 of June 2026, with the first rollout being Risk-Based Conditional Access as part of the Entra ID P2 licence included in the suite. This policy enforces dynamic, risk-aware authentication, meaning that the system continuously evaluates the risk level of every sign-in and responds automatically.

What Happened

The user received a phishing email crafted to appear legitimate, delivered through Constant Contact’s email infrastructure. The email contained a tracked redirect link that routed the user’s browser through an Adversary-in-the-Middle (AiTM) proxy, a sophisticated attack technique where the attacker sits invisibly between the victim and Microsoft’s login page, intercepting credentials, MFA approvals, and session cookies in real time.

The attacker’s infrastructure (161.193.9.164) was already known to Microsoft’s threat intelligence platform (TITAN) and had been previously identified by Microsoft from attacks against other organisations. The attacker operated behind Tor/anonymising VPN to conceal their identity and location.

The Compromise & Automated Response

4:12 PM  Compromise

The user clicked the phishing link and entered his credentials. The attacker captured his password in real time. Microsoft’s Conditional Access policy blocked the sign-in pending MFA, but because the user’s browser was being proxied, the MFA push was intercepted too. The user approved what he believed was a legitimate MFA notification.

4:13 PM  Persistence attempt

The attacker obtained a valid authenticated session token, full access to the user’s Microsoft 365 account. The attacker immediately registered their own iPhone XS as a second MFA authenticator on the user’s account, an attempt to establish persistent access that would survive a password reset.

4:19 PM  Automated response

Defender/Entra detection engines confirmed the compromise. The Defender Suite protection features fired automatically: all of the user’s active session tokens were immediately invalidated, the attacker’s stolen session was killed, and the user’s account was flagged for forced remediation. No human intervention triggered this. The immediate threat was completely neutralised.

4:32 PM  Recovery

The user completed a self-service password reset. Entra Connect automatically synchronised the new password to the on-premises Active Directory server, ensuring both cloud and on-premises credentials were rotated simultaneously. Refresh tokens were invalidated a second time as part of this process.

4:34 PM  Recovery

The user removed the attacker’s iPhone XS from his registered MFA devices via My Account.

4:36 PM  Resolved

A final Entra Connect sync confirmed full reconciliation of the user’s account across cloud and on-premises environments.

Conclusion

This incident demonstrates exactly the value proposition of the Defender suite deployment. A sophisticated, targeted AiTM attack, the kind specifically designed to defeat standard MFA, was caught, contained, and remediated automatically, in 6 minutes, on a Tuesday late afternoon, without any manual intervention required for containment.

The real test of your cyber security isn’t whether you’re attacked. It’s what happens when you are.

Talk to an ABT Specialist

If you’re unsure whether your Microsoft environment could detect and automatically contain a sophisticated attack like this, talk to an ABT Specialist about reviewing your security posture and making sure the right protections are in place.

Get in touch

Sign up to our Business Newsletter

Sign up for the latest news, product or service offerings, and get invites to our events or webinars.