Bypass Record
Valid Accounts × Microsoft 365
A publicly-reported instance of Valid Accounts bypassing Microsoft 365, recorded with its original source. Factual record; no assessment of any specific deployment.
Mechanism
Attackers used a phishing kit that injects custom JavaScript to manipulate the Microsoft 365 login page, disabling FIDO2 hardware key authentication and forcing fallback to weaker methods. After the victim authenticates, the kit steals the authenticated session cookie, enabling account takeover without needing the hardware key.
Detection & mitigation
Monitor for impossible travel, unusual login locations, or new device enrollments following phishing reports. Enforce conditional access policies that require compliant devices and block legacy authentication. Use endpoint detection to identify suspicious browser processes or cookie theft attempts.
This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.