Bypass Record

Valid Accounts × Microsoft 365

A publicly-reported instance of Valid Accounts bypassing Microsoft 365, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
Microsoft 365
Technique
Valid Accounts
MITRE ATT&CK
T1078
Confidence
High
Severity
High
Status
in the wild
Disclosed
2026-09-08
Config / version noted
Not stated

Provenance

Reported as

custom JavaScript to disable FIDO2 hardware key authentication before stealing authenticated session cookies

Mechanism

Attackers used a phishing kit that injects custom JavaScript to manipulate the Microsoft 365 login page, disabling FIDO2 hardware key authentication and forcing fallback to weaker methods. After the victim authenticates, the kit steals the authenticated session cookie, enabling account takeover without needing the hardware key.

Detection & mitigation

Monitor for impossible travel, unusual login locations, or new device enrollments following phishing reports. Enforce conditional access policies that require compliant devices and block legacy authentication. Use endpoint detection to identify suspicious browser processes or cookie theft attempts.

Valid Accounts has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.