Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Microsoft reported that an adversary-in-the-middle (AiTM) phishing campaign targeted more than 35,000 users across more than 13,000 organizations in 26 countries from April 14–16, 2026. The campaign used fake workplace conduct and compliance notices to lead recipients through attacker-controlled pages to a Microsoft sign-in flow designed to capture authentication tokens. Those figures describe targets—not confirmed account takeovers; Microsoft did not publish a compromise count for this campaign.

How the April 2026 campaign worked

Microsoft Defender Research observed the activity between April 14 and 16, 2026. Ninety-two percent of targeted users were in the United States. The largest reported industry shares were healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%). These are shares of the campaign’s targets, not successful compromises. Microsoft’s campaign analysis does not state how many recipients entered credentials, how many tokens were captured, or how many accounts were confirmed compromised.

The compliance lure

The messages presented themselves as internal regulatory or employee-conduct notices. Reported display names included “Internal Regulatory COC,” “Workforce Communications,” and “Team Conduct Report”; subjects referred to an internal case log or non-compliance case. The email claimed a code-of-conduct review had begun and urged the recipient to view personalized case materials in a PDF attachment. A link in the PDF sent the recipient through attacker-controlled pages, including CAPTCHA and intermediate prompts, before presenting a Microsoft sign-in route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The sign-in and token theft

At the final stage, selecting “Sign in with Microsoft” redirected the victim to a Microsoft authentication page within an AiTM session-hijacking flow. The attacker’s proxy relayed the authentication traffic and sought to capture the resulting validated token or session cookie. Microsoft confirmed the AiTM portion of the chain. It said the preceding stage had some hallmarks of device-code phishing, but did not confirm that device-code phishing was used in this campaign.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What an adversary-in-the-middle attack is

An AiTM attack inserts an attacker-controlled proxy between a person and a legitimate identity provider. Rather than merely collecting a password on a fake page, the proxy can relay a live authentication exchange to the real service. The victim may see a convincing sign-in experience and complete a familiar multi-factor authentication (MFA) prompt, while the attacker captures a validated session token or cookie and uses it to access the account.

This is why an MFA prompt by itself does not prove a sign-in is safe. Some conventional MFA methods can be relayed in a real-time phishing flow. MFA that resists phishing binds authentication to the legitimate service or origin, making it substantially harder for an attacker’s proxy to reuse the login. The Canadian Centre for Cyber Security’s guidance identifies phishing-resistant MFA as the mitigation for known AiTM campaigns.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to recognize a fake conduct or compliance notice

A compliance subject line can create pressure to act quickly, but the theme alone does not establish whether a message is legitimate. Treat an unexpected notice as a request to verify, not as a reason to open an attachment or sign in through its link.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Check whether the case or review is known to your organization, using a trusted channel such as your usual HR, legal, or compliance contact details—not contact information in the message.
  • Be cautious of personalized case materials delivered as an unexpected PDF, especially when the PDF sends you to a sign-in page.
  • Do not treat a CAPTCHA, familiar Microsoft branding, or a successful MFA prompt as proof that a link is safe.
  • Report suspicious messages through your organization’s established phishing-reporting process. Administrators can investigate the message and its link without requiring employees to test it themselves.

How organizations can reduce AiTM risk

No single email filter or awareness measure guarantees prevention. Microsoft’s campaign-specific recommendations combine mail, browser, identity, and response controls; the Canadian Centre emphasizes phishing-resistant authentication and access restrictions.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Use phishing-resistant sign-in methods

Where the identity provider and users’ devices support them, consider FIDO2 security keys, passkeys, or Windows Hello for Business. These methods are designed to resist credential relay and phishing. A physical FIDO2 key is one option, but check compatibility with the organization’s identity provider, operating systems, device ports, accessibility needs, recovery procedures, and account-lockout policies before selecting or deploying one. Review fallback methods as well: a stronger primary method offers less protection if weaker, relayable options remain available for routine sign-in.

Restrict and monitor access

Use conditional-access policies that require registered devices or limit sign-ins to organization-controlled IP ranges where appropriate. The Canadian Centre reports that, in its analyzed and categorized campaign sample from 2023 through mid-2025, living-off-trusted-sites techniques accounted for 59% of cases and conventional methods for 41%. In the same Canadian government and critical-infrastructure dataset, full-session compromises represented 6.1% of categorized outcomes in 2025 Q2, down from a high of 17.4% in 2023 Q3. The Centre attributes the decline primarily to adoption of registered-device and phishing-resistant MFA conditional-access policies and IP restrictions. These figures describe that separate sample, not the April 2026 global campaign.

Rank #4
Fluke Networks 10660001 Security Key Insert for Can Wrenches
  • Reversible insert tool for can wrenches.
  • One end for SLC Cabinets. Other end for pin in head screws found in most Network Interface boxes.

Layer email and endpoint protections

Microsoft recommends reviewing Exchange Online Protection and Microsoft Defender for Office 365 settings; using Zero-hour auto purge, Safe Links, and Safe Attachments; enabling network protection and browsers with Microsoft Defender SmartScreen; and using user-awareness training and phishing simulations. It also recommends automatic attack disruption. These controls can reduce exposure or help contain activity, but should complement rather than replace phishing-resistant authentication and incident response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you signed in through a suspicious link

If you entered credentials or approved a sign-in after following an unexpected link, contact your organization’s security or IT team promptly and use a trusted channel. Do not assume that changing the password alone ends an active session: a stolen token or cookie may remain usable until the session is revoked.

For response actions beyond the April campaign’s published findings, Microsoft’s report on a separate January 2026 AiTM and business-email-compromise campaign says responders should revoke session cookies, review changes to MFA, and remove suspicious inbox rules as well as reset credentials. Your security team should assess sign-in activity and account changes, revoke sessions where appropriate, and follow its incident-response process. The January report is a separate incident account, not evidence that those specific changes occurred in the April campaign. Microsoft’s January 2026 response guidance.

AiTM activity reported after the April campaign

In September 2026, CERT-EU described a separate global campaign, reported by Microsoft as active since May 2026. It involved passkey- and SSO-themed social engineering, AiTM sites or device-code authentication flows, and account takeover and data theft from Microsoft 365 services. This later activity is distinct from the April code-of-conduct campaign; the available reporting does not establish that the April operation continued or shared attribution. CERT-EU’s September 2026 brief.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.