Stolen Exec Email Sends RFP Lure to Steal M365 Logins

The Register Security · Medium sophistication
Last updated October 8, 2026

A construction/landscaping firm’s executive email account was compromised and used to send convincing “request for proposal” (RFP) emails to another company, tricking recipients into entering Microsoft 365 credentials and an MFA code on a fake login page. The attackers used a man-in-the-middle workflow so Microsoft sent the real SMS code, which the victim then unknowingly handed over via the phishing site. In a separate case, a small construction company that declined security help was later hit by ransomware and shut down within months after backups were also encrypted.

How the attack worked

Attackers first compromised the email account of an executive at a construction/landscaping firm. From that trusted mailbox, they sent phishing emails to a partner company framed as RFPs, requests for proposal. Instead of an attached document, the email included a download button. Clicking it led recipients to a page that looked identical to the real Microsoft 365 login screen but was hosted on a domain other than microsoft.com.

Because the targeted user had two-factor authentication enabled, the fake page also asked for a limited-time 2FA code. The attackers relayed the stolen username and password to Microsoft's real login system in real time, which triggered a genuine SMS code to be sent to the victim. The victim then typed that real code into the fake page, handing the attackers everything needed to complete a man-in-the-middle session takeover.

Why it succeeded

The lure worked because it came from a real, known contact rather than a stranger. An RFP is an attractive, plausible reason for a partner company to reach out, and recipients who had interacted with the sender before had little reason to be suspicious. The attackers also created email filtering rules inside the compromised executive's mailbox to hide outgoing campaign messages, reducing the chance the real user would notice the abuse of their own account.

What to watch for

  • Unexpected RFP, quote, or new-business requests delivered as a link or download button rather than a normal attachment
  • A Microsoft 365 login page that is not on the microsoft.com domain
  • A prompt to enter a one-time 2FA code into a web page just to view a document
  • Unusual mailbox filtering rules that could be hiding malicious outgoing mail

How to build resistance

Detection tooling in this case identified the anomalous login and revoked the session token within minutes, which limited how long the attackers could operate. Organizations can reduce the risk of similar incidents by treating unsolicited business requests as higher risk and verifying them through a separate known contact channel before clicking any link. Checking the web address before entering any credentials is a simple but effective habit. Because one-time SMS codes can be relayed by attackers in real time, moving high-value users to phishing-resistant MFA such as hardware security keys or passkeys closes off this specific man-in-the-middle technique entirely, since there is no code for an attacker to intercept and reuse.

Key findings

  • Attackers compromised an executive’s email at one company and used it to phish a partner company with realistic business-themed messages (RFPs).
  • The phishing email used a download button (link) instead of an attachment, leading to a fake Microsoft 365 login page on a non-microsoft.com domain.
  • The fake login page also asked for a limited-time 2FA code; the attackers relayed credentials to Microsoft so the victim received a real SMS code, enabling a man-in-the-middle takeover.
  • Attackers created email filtering rules in the compromised executive mailbox to hide campaign messages from the real user.
  • Detection tooling identified the anomalous login and revoked the session token within minutes, limiting attacker dwell time.
  • A different small construction company suffered ransomware after relying on an old unpatched Windows server and a connected backup drive that was encrypted along with primary data, contributing to business failure.

Who’s being targeted

  • Commonly targeted roles: Executives, Sales, Operations/Estimating, Finance, IT/Helpdesk, All Microsoft 365 users.
  • Affected industries: Construction, Landscaping services.
  • Attack channels: email, website.
  • Impersonated: A known partner company (using a real executive’s compromised email account).

Red flags to watch for

  • The Microsoft 365 login page is "not on the microsoft.com domain"
  • Unexpected prompt to enter an MFA code into a web page to view an RFP
  • RFP delivered via a button/link instead of a normal attachment (PDF/PowerPoint)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers steal Microsoft 365 credentials in this attack?

Attackers compromised an executive's email account and sent RFP-themed phishing emails to a partner company. Clicking a download button led victims to a fake Microsoft 365 login page not hosted on the microsoft.com domain, where they entered their credentials and a 2FA code.

How did the attackers bypass two-factor authentication?

The fake login page relayed the stolen credentials to the real Microsoft site in real time, prompting Microsoft to send a genuine SMS code. The victim entered that code on the phishing page, completing a man-in-the-middle takeover.

What made this phishing email convincing?

The email came from a real, previously compromised executive mailbox and was framed as a legitimate RFP (request for proposal), a lure designed to look like a genuine new business opportunity from a known contact.

How can organizations defend against this kind of attack?

Awareness takeaways include verifying unexpected RFP or quote requests through a separate known contact method, checking login page domains before entering credentials, and moving to phishing-resistant MFA such as hardware keys or passkeys.

Read the video transcript

An exec’s real email gets hacked, then used to send you a shiny new RFP. Looks like easy new business, right? You click the download button and land on a perfect-looking Microsoft 365 login page that even asks for your limited-time SMS code. But the web address is not microsoft.com. Here’s the trick: this is a man-in-the-middle. When you type your password and SMS code, they relay it to Microsoft in real time and walk straight into your M365 account as you. If an RFP or quote email makes you click a link and log in, stop and call your known contact to confirm before you touch that download button.

Similar attacks

Fake Agreements Hide RMM Backdoors as “Normal IT”

Fake Agreements Hide RMM Backdoors as “Normal IT”

Huntress reports attackers are increasingly installing legitimate remote monitoring and management (RMM) tools after a phishing click, giving them persistent remote control that can blend in with normal IT activity. The article also describes common identity-focused schemes like hidden mailbox…

October 5, 2026
QR-PDF Phishing Hits M365, MFA Bypass Surges

QR-PDF Phishing Hits M365, MFA Bypass Surges

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies,…

July 28, 2026
Nikkei Email Account Hijacked to Send 9,000 Phish

Nikkei Email Account Hijacked to Send 9,000 Phish

Nikkei said an attacker took over an employee’s Microsoft 365 email account and used it to send about 9,000 phishing emails to people who had previously communicated with Nikkei staff, including journalistic sources. The messages contained links leading to malicious websites, creating a high-trust…

October 5, 2026
China-Linked TA419 Phishes US AI Policy Experts

China-Linked TA419 Phishes US AI Policy Experts

Proofpoint linked China-nexus actor TA419 to credential-phishing campaigns aimed at U.S. AI policy experts, including people at think tanks. The attacker impersonated well-known AI policymakers and an Anthropic executive, using believable “advisory committee” and “research questions” emails to draw…

October 2, 2026
China-Linked Phish Targets AI Policy Experts

China-Linked Phish Targets AI Policy Experts

Proofpoint reports a China-aligned espionage group (TA419) targeted U.S. AI policy experts at think tanks, universities, and law firms using phishing emails that impersonated well-known officials and AI industry figures. The attackers tried to start a conversation first, then sent a shortened link…

October 1, 2026
EvilTokens Used Device-Code Phish + AI for BEC

EvilTokens Used Device-Code Phish + AI for BEC

Microsoft disrupted EvilTokens, a phishing-as-a-service operation linked to thousands of compromised Microsoft 365 inboxes. The group used “device code” phishing to steal valid session tokens (not passwords) and then used an AI chatbot to scan mailboxes and help craft business email compromise…

September 22, 2026