Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Microsoft Threat Intelligence reported in July 2022 that a campaign had attempted to target more than 10,000 organizations since September 2021. That figure describes attempted targeting—not confirmed compromises—and is a historical count, not a measure of current activity. The warning matters because the campaign used adversary-in-the-middle (AiTM) phishing to steal authenticated session cookies, which can let an attacker reuse a session even after a user completes multifactor authentication (MFA).

What Microsoft reported

In its July 12, 2022 report, Microsoft Threat Intelligence said that iterations of an AiTM campaign had attempted to target more than 10,000 organizations since September 2021. Microsoft linked those iterations through their targeting and post-compromise activity. The statistic does not establish that every targeted organization was compromised.

In the campaign Microsoft described, HTML attachments and redirector pages led users to a phishing site built with Evilginx2 that spoofed Office 365 authentication. Those are details of the observed campaign, not a template for every AiTM attack.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How an AiTM phishing attack works

An adversary-in-the-middle attack places an attacker-controlled proxy between a user and the legitimate sign-in service. Rather than merely displaying a static imitation page and collecting a password, the proxy relays the live authentication exchange. If the user successfully signs in, the proxy can capture the resulting session cookie. The attacker may then replay that cookie to use the authenticated session without completing the sign-in again.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For users, the visible URL is an important clue: the address may not be the legitimate service’s domain. A convincing page or a successful MFA prompt does not prove that the sign-in is taking place directly with the real service.

Why MFA may not stop session theft

MFA helps protect an account by requiring more than a password at sign-in. In this attack, however, the attacker relays the authentication process and targets the session created after sign-in. If an attacker obtains a usable session cookie, they can act through that already-authenticated session rather than asking the identity provider to authenticate them again.

Rank #2
FEITIAN K9 USB A NFC - Two Factor Authenticator (2FA) - Multi-Factor Authentication (MFA) - Device Security Key + FIDO2 - Achieve Advanced Account Protection
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Secured by NXP semiconductors
  • Works in every browser and application without installing any drivers
  • Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.

Microsoft Threat Intelligence explained the distinction directly: “Note that this is not a vulnerability in MFA; since AiTM phishing steals the session cookie, the attacker gets authenticated to a session on the user’s behalf, regardless of the sign-in method the latter uses.” The risk described is session theft and replay, not a flaw in MFA itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What attackers can do with an authenticated mailbox

Microsoft observed stolen credentials and cookies being used to access mailboxes and enumerate sensitive data. Access to a real, authenticated mailbox can also support business email compromise, including attempted payment fraud. A phishing incident can therefore progress from a user’s sign-in to activity that appears to come from a legitimate account.

Rank #3
FEITIAN K40 USB Security Key - Two Factor Authenticator - USB-C with NFC, FIDO2 - Help Prevent Account Takeovers
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
  • Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
  • Durable design made to last for a long time with everyday use. Water-resistant (IP67)
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.

How organizations can reduce token-theft risk

Microsoft’s current Entra token-protection guidance frames defense in layers: reduce the chance of compromise, detect and mitigate successful theft, and prevent or limit replay. The precise controls available depend on an organization’s identity configuration, devices, applications, and support for specific features.

  • Use phishing-resistant authentication where supported. Microsoft identifies passkeys and FIDO2 security keys as phishing-resistant options. Its guidance also names Windows Hello for Business and certificate-based authentication for private applications. These are parts of a configured identity-security program, not a guarantee against every account or session risk.
  • Harden devices and apply appropriate Conditional Access controls. Microsoft recommends device hardening and suitable Conditional Access policies. Organizations should configure controls for their supported devices and applications rather than assuming one policy covers every sign-in.
  • Monitor for suspicious token activity. Detection and response are necessary because prevention can fail. Establish monitoring and an incident process for suspicious sign-ins or token use, then investigate and mitigate suspected compromise.
  • Use Token Protection where supported. Microsoft recommends Token Protection to prevent or limit replay in supported scenarios. Confirm the feature’s applicability to the organization’s identity environment and workloads.
  • Restrict device-code flow to legitimate needs. Microsoft also recommends limiting this authentication flow to cases where it is required.

A FIDO2 security key may be one suitable phishing-resistant option, but buying a key alone does not secure an organization. Confirm identity-provider support, application coverage, and configuration before relying on it as a control.

Rank #4
Thales - SafeNet eToken FIDO - FIDO2 Certified Security Key - Passwordless Phishing-Resistant Authentication for Web Apps, Devices & Desktops - USB-C - Pack of 1
  • FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the 2022 warning separate from later campaign figures

Microsoft Defender Research reported a separate campaign observed April 14–16, 2026, involving more than 35,000 users across over 13,000 organizations in 26 countries. Those figures belong to that later campaign; they are not an update to the 2022 campaign’s attempted-targeting count. The 2026 report said the United States represented 92% of targets in that campaign and reported industry shares of 19% healthcare and life sciences, 18% financial services, 11% professional services, and 11% technology and software.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Swissbit iShield Key 2 FIDO2 USB-C Security Key with NFC – FIDO Certified, Passwordless Authentication, Passkey & U2F, Phishing-Resistant Security for Enterprise
  • SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
  • PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
  • COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
  • DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
  • USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.