Between April 14 and April 16, 2026, a single phishing campaign harvested session tokens from more than 35,000 users across 13,000 organizations in 26 countries. Every victim was using multi-factor authentication. Not weak MFA. Not SMS codes. Standard Microsoft Authenticator push notifications — the control that most Canadian businesses have been told is sufficient.
The campaign did not steal passwords. It did not intercept authentication codes. It bypassed MFA entirely by stealing the session tokens that Microsoft issues after authentication is successfully completed. By the time the attacker used those tokens to log into email, payroll systems, and financial platforms, the MFA check was already behind them.
This is the Microsoft 365 threat that every Canadian business running M365 needs to understand right now — because Canada is not a collateral target. It is the primary one.
Adversary-in-the-Middle (AiTM) phishing works differently from the attacks that standard MFA was designed to stop. Traditional phishing steals credentials. The user types their password into a fake login page, and the attacker uses that password to log in. MFA blocks this because the attacker does not have the second factor.
AiTM phishing does not steal credentials. It steals proof of authentication.
Here is what actually happens. The user receives a phishing email and clicks through to a page that looks exactly like a Microsoft 365 login page. The page is a real-time reverse proxy operated by the attacker. When the user enters their credentials and approves the MFA prompt on their phone, the proxy forwards everything to the real Microsoft servers, which authenticate the session and issue a session token. The proxy captures that token before passing the successful login back to the user. The user sees a normal sign-in. The attacker now holds a live session token good for roughly eight hours.
That token is all the attacker needs. They log into the user’s Microsoft 365 account directly, with no password and no MFA prompt, because authentication already happened. The MFA check is not in the future. It is in the past.
In April 2026, Microsoft Threat Intelligence published a case study on a financially motivated threat actor it designates Storm-2755. What distinguishes Storm-2755 from most threat actors is that its victim-selection criterion is not industry, revenue, or technology stack. It is geography. Storm-2755 targets Canadians specifically.
The attack chain works like this. Malvertising and search engine optimization poisoning push sponsored content into the results that appear when a Canadian employee searches for Microsoft 365 sign-in links. The victim clicks through to a legitimate-looking login page that is actually an AiTM proxy. Credentials and session token are captured. The attacker then accesses Workday or the organization’s HR platform and rewrites the victim’s salary deposit account. The next payroll cycle deposits the employee’s salary into the attacker’s account.
In its 2025 guidance publication, the Canadian Centre for Cyber Security reported detecting more than 100 AiTM phishing campaigns specifically targeting Canadian Microsoft Entra tenants between 2023 and early 2025. That figure predates Storm-2755’s documented activity surge in 2026. Canadian organizations in healthcare, government, manufacturing, and professional services were confirmed targets in July 2026 alone.
Canada is not experiencing spillover from campaigns designed for other markets. Canadian employees, Canadian payroll systems, and Canadian Microsoft 365 tenants are the intended targets.
A live Microsoft 365 session token gives an attacker access to everything the user has. Email. SharePoint files. Teams messages. OneDrive. Any application connected to the Microsoft identity layer through single sign-on. The attacker uses automated tools to search mailboxes for specific patterns: payroll communications, direct deposit information, banking details, client financial records, wire transfer instructions.
From there, the attack branches. The payroll redirect is the most direct: change the salary deposit account and wait for the next pay cycle. Business email compromise is the higher-value path: reading the victim’s email, the attacker impersonates them with contextual accuracy of their writing style, their open threads, and their current projects to authorize fraudulent transactions or extract colleagues’ credentials. The 2026 Verizon Data Breach Investigations Report puts the median loss per BEC incident at CA$50,000. In the cases that surface publicly, the actual losses are often higher.
The session token typically stays live for eight hours, maintained by automated activity at regular intervals. Most organizations do not detect an AiTM intrusion in that window. The attack is over before monitoring tools detect anything unusual.
What made AiTM attacks niche three years ago — the technical complexity of building and operating a reverse proxy infrastructure — is no longer a constraint. Phishing-as-a-Service platforms sell AiTM capability as a subscription. Tycoon 2FA, the dominant platform before a Microsoft and Europol-led coalition seized 330 of its active domains on March 4, 2026, had been used in attacks against approximately 500,000 organizations since 2023. The takedown did not reduce overall AiTM attack volume — it fragmented the market into successor platforms, of which Kali365 (first observed in April 2026 and the subject of an FBI Public Service Announcement on May 21, 2026) is currently the most active.
A threat actor running one of these platforms needs no deep technical knowledge. They select a target organization, customize a phishing email template, deploy the AiTM proxy infrastructure (provided by the platform), and wait for a credential and token to arrive. The platforms include dashboards, analytics, and customer support. The barrier to running a sophisticated AiTM campaign against a Calgary professional services firm is now approximately the same as the barrier to running a basic credential phishing campaign was five years ago.
The important clarification is that standard MFA is not useless. It stops credential-only attacks, which still represent a significant share of intrusions. A business without any MFA is in a materially worse position than one with standard push-based MFA. The problem is that the attacks specifically targeting Canadian Microsoft 365 tenants in 2026 are not credential-only attacks. They are token theft attacks, and standard MFA has no mechanism to stop them.
Phishing-resistant MFA does. The distinction matters because the two types look similar from the outside — both require something beyond a password — but they work on fundamentally different principles.
Standard MFA (push notifications, TOTP codes, SMS) authenticates the user’s identity at login. Once the session token is issued, the MFA check is complete. An attacker with the token bypasses all future MFA requirements because they never need to log in again — they are already authenticated.
Phishing-resistant MFA (FIDO2 hardware keys, Windows Hello for Business, passkeys) binds the authentication to the specific device and the specific website being accessed. A FIDO2 credential generated for login.microsoftonline.com cannot be used on an AiTM proxy page, even if that page looks identical to the Microsoft login. The cryptographic binding to the legitimate domain is enforced at the hardware level. The proxy intercepts nothing useful.
These steps address the specific AiTM threat documented against Canadian organizations in 2026. They are listed in priority order. The first two provide the most meaningful risk reduction for most businesses and can be implemented without replacing existing hardware.
The majority of Canadian SMBs running Microsoft 365 have configurations that made sense when they were set up and have not been reviewed since. Microsoft ships M365 with settings designed for backwards compatibility across the widest possible range of customers — not for the specific threat environment facing a Canadian professional services firm or healthcare provider in 2026. Default M365 is not insecure. It is under-secured for what Canadian organizations are actively managing.
The controls that stop AiTM attacks — phishing-resistant MFA, Conditional Access with device compliance requirements, session token lifetime management, Continuous Access Evaluation, Defender for Office 365’s anti-phishing intelligence — are available in M365 Business Premium. Most organizations that have Business Premium licences have not configured these features. They are paying for the protection without enabling it.
A Microsoft 365 security review from a managed IT provider takes two to four hours and produces a prioritized list of configuration changes with specific implementation steps. It is not a complex project. It is a configuration audit against known effective controls for known current threats. The difference between an M365 tenant that reviewed and hardened its security configuration in 2026 and one that has not is the difference between catching an AiTM intrusion attempt at the authentication layer and discovering the payroll fraud three weeks after the pay cycle ran.
The conversation Canadian businesses need to have about Microsoft 365 security in the second half of 2026 is not about whether MFA is enabled; most organizations that have done the basics have MFA enabled. The conversation is about whether the MFA they have enabled is the kind that stops the attacks that are actually running against Canadian targets right now.
Storm-2755 is not a theoretical threat. It ran against confirmed Canadian targets in healthcare, government, manufacturing, and professional services in July 2026. The technique it uses bypasses every standard MFA control that most Canadian SMBs have deployed. The defence exists, is available in licences many businesses already pay for, and takes hours to implement correctly.
The gap between “we have MFA” and “we are protected against what is hitting Canadian Microsoft 365 tenants right now” is the conversation worth having before a pay cycle runs short.
Tecbound manages Microsoft 365 security for businesses in Calgary and across Canada, including Entra ID configuration, Conditional Access policy, phishing-resistant MFA deployment, and security log monitoring. This kind of exposure is exactly the sort of gap regulators are watching more closely under new obligations like Bill C-8. Contact us at tecbound.com/contact-us.
Standard MFA — push notifications, authenticator app codes, SMS — protects against credential theft but not against AiTM (adversary-in-the-middle) attacks. AiTM phishing does not steal your password or your MFA code. It steals the session token that Microsoft issues after you have already authenticated successfully. By the time the attacker uses that token, your MFA check is already in the past. Phishing-resistant MFA — FIDO2 hardware keys, Windows Hello for Business, passkeys — stops this by binding the credential cryptographically to the specific legitimate website, so an AiTM proxy cannot capture anything usable.
Storm-2755 is a financially motivated threat actor documented by Microsoft Threat Intelligence in April 2026. It is notable because its victim-selection criterion is geography rather than industry — it specifically targets Canadian employees. Its primary attack is an AiTM phishing campaign that hijacks Microsoft 365 sessions and redirects salary deposits in Workday. Canadian organizations in healthcare, government, financial services, and professional services were confirmed targets in 2026. It is the first Microsoft-attributed threat actor whose primary target is Canada specifically.
Regular MFA (push notifications, TOTP codes) verifies your identity at login. Once the session token is issued, the MFA check is done. An attacker who intercepts that token can use it without triggering another MFA prompt. Phishing-resistant MFA (FIDO2 hardware keys, passkeys, Windows Hello for Business) binds the authentication cryptographically to the specific device and the specific legitimate website. An AiTM proxy page receives nothing usable from the exchange — the credential is device-bound and domain-bound, so it does not work on an imitation site. FIDO2 keys are available for approximately CA$50 to CA$80 each and are compatible with Microsoft 365 Business Premium at no additional authentication cost.
AiTM sessions have a characteristic pattern in Microsoft Entra sign-in logs: successful authentication from a known device and location, followed by token use from a residential proxy IP range in a different geography, with keepalive activity at regular approximately eight-hour intervals. Most organizations do not actively monitor Entra sign-in logs for these patterns. A managed IT provider with Microsoft security expertise can implement automated alerting so these anomalies surface before the attacker has completed their objective. If you suspect an active compromise, Microsoft’s Incident Response team and the Canadian Centre for Cyber Security’s reporting line (cyber.gc.ca) are the appropriate first contacts.
The confirmed targets of Storm-2755 and the broader AiTM campaign activity in Canada include organizations of all sizes. The attacker’s interest is not company size — it is access to payroll systems and financial accounts. A 20-person professional services firm in Calgary with a Workday or ADP payroll integration and a Microsoft 365 environment is within the target profile. The AiTM tooling available through Phishing-as-a-Service platforms has reduced the cost of running these campaigns to the point where targeting smaller organizations is economically rational for attackers.
Microsoft 365 Business Premium includes Conditional Access, Microsoft Entra ID P1 (which enables the Conditional Access policies needed to block legacy auth and device code flows), Defender for Office 365 Plan 1 (anti-phishing, safe links, safe attachments), and Continuous Access Evaluation. FIDO2 and Windows Hello for Business authentication are supported at no additional authentication cost on Business Premium. Microsoft 365 Business Standard and Business Basic do not include Conditional Access or Defender for Office 365 — organizations on those licences are running M365 without the controls that matter most against AiTM attacks.
Get A FREE Subscription To Weekly Cybersecurity Tips So Your Company Doesn’t Become The Next Victim.