The standard advice for years has been that multi-factor authentication is the best single thing you can do to protect your accounts, and that's still worth following. However, the attacks we're dealing with week to week have stopped trying to beat it, and started going around it. So what are they actually after?
It's now your session they want, not your password
MFA did genuinely kill off the attacks it was designed to stop, and none of what follows is a reason to turn it off. An account with MFA enabled is always massively more secure than one that isn't. However, when you sign into Microsoft 365, your browser is handed something that keeps you signed in. This is why you're not forced to enter your password and a code every five minutes for the rest of the day. That's your session, and this is what attackers now want to get hold of.
It's worth more than your password for two reasons. A password and a code get somebody one login. A stolen session is ongoing access to your mailbox without authenticating again at all. And because it doesn't need your password, changing your password doesn't necessarily solve the problem.
Which means there's more than one way in
The version most people have heard about is the convincing fake login page. It sits between you and the real Microsoft site and passes everything along in real time, so whatever your second step normally is (typing a code, or tapping "approve" on your phone) it happens at the genuine end a second later and the attacker keeps the session that comes out.
But there are routes that don't involve a fake page at all. Some prompt you to approve something on Microsoft's own site, where every URL is legitimate and there's nothing mispelt to notice, and the attacker still ends up holding access at the end of it. And some skip the login entirely. Certain types of malware simply lift saved sessions off the machine, which means there's no suspicious email involved anywhere. In every one of those cases MFA did exactly what it was built to do, but it wasn't enough.
Awareness training can and does help. We run simulated phishing campaigns for a number of clients. In one campaign we ran recently, pretty much everyone realised it was a dodgy email. They either reported it, deleted it or ignored it. Everyone except one...Unfortunately, it only takes one. And that person usually isn't careless. They're busy, or the email arrived exactly when they were expecting something similar. Any approach that needs every member of staff to get it right every single time will eventually fail. And for the malware route, there's nothing for them to spot in the first place.
I give up!
We hear you, but unfortunately this exactly how this cycle always works. We introduce a mitigation against the route people are using into accounts which works brilliant for a while, and then the attacks eventually catch up and start trying to work around whatever that mitigation is.
So what can be done this time? There's no single setting that closes all of this, but there are a mixture of approaches that attempt to address it. Passkeys, security keys and Windows Hello are the strongest fix for the fake login page, because they check they're talking to the real site and simply won't work on a lookalike. Equally, restricting sign-ins to company-managed devices is the one of the more useful protections, because a stolen session on somebody else's machine stops being much use.
Blocking sign-ins from outside the UK is very effective against the high-volume attacks that make up most of what our clients see. We recently found a month of attempts against one account from abroad. Every one of these attempted logins was refused, with no sign anybody ever got inside. This protection is less useful in the unlikely but possible event someone's decided to target your account personally for some reason.
It should be noted that most of the above needs a 365 Business Premium licence rather than Business Standard, which is a few pounds per user per month. However, set that against what a compromised mailbox actually costs you in time and potential invoice fraud, and it isn't usually a close call.
If you're ever even remotely suspicious any of the above or something similar may have happened to you, just let us know rather than attemping to deal with it yourself and we'll give everything a check over for you. Because of the session problem above, a password change on its own doesn't reliably lock anybody out. Active sessions need revoking and authentication methods clearing and re-registering too. It takes minutes, and it's the difference between shutting the door and changing the lock while somebody's still inside. Equally, if you're not sure what's currently in place on your own 365 tenant, get in touch and we'll take a look.