Skip to content
Back to Guavy Wire
Stocks

Phishing Campaign Compromises Microsoft 365 Accounts Using AiTM Techniques

Instruments
MSFT
Share

A sophisticated phishing campaign has been identified by Arctic Wolf, targeting organizations across various sectors and regions. The campaign uses adversary-in-the-middle (AiTM) techniques to compromise Microsoft 365 accounts and collect related email associated with personnel involved in financial workflows.

The phishing emails impersonate an automated call notification service and direct recipients to a fraudulent voicemail portal. Once access is established, the actor quietly maintains compromised sessions and collects email data.

The campaign shares significant technical and behavioral overlap with the 'Payroll Pirates' activity cluster Microsoft tracks as Storm-2755. Arctic Wolf's investigation identified affected individuals across multiple geographic regions, suggesting a wider scope of targeting than originally reported.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc