The call came in from a client we'd recently signed onto a Managed Service Contract. We were mid-onboarding — we hadn't even reached the security phase yet — and they were in a panic.
They'd just paid £60,000 to someone pretending to be their supplier. The money was genuinely owed. The invoice was expected. But the bank details belonged to a criminal, and the money was gone.
Here's how it happened — and what it taught us about protecting every client we take on.
The attack: it started weeks before the money moved
Weeks earlier, someone at the business had clicked a link in an email. It took them to what looked like a Microsoft 365 login page. They signed in, nothing appeared to happen, and they thought no more of it.
That was the moment the attacker got in. This was a session hijacking attack: the fake login page stole a session cookie — the small token that lets you stay signed in to Microsoft 365 without authenticating every time. In the wrong hands, that cookie gives someone else full access to your account. And because the attacker steals an already-authenticated session, this technique bypasses multi-factor authentication entirely. That's what makes it so dangerous.
The threat actor — most likely operating from the US — didn't do anything rash. They quietly read through the mailbox, looking for a conversation worth exploiting. They found one: the client had recently finished renovation works on their office, and roughly £60k was due to the supplier now the work was complete.
The takeover: hiding the real supplier
With a payment on the horizon, the attacker made their move.
First, they created a mailbox rule that silently forwarded any email from the genuine supplier into an obscure folder in the client's Outlook. Real messages from the real supplier simply stopped appearing in the inbox — and nobody noticed.
Then the attacker stepped into the conversation themselves, sending emails that spoofed the supplier's own domain. The email address matched. The signature matched. The tone and thread history matched. Everything was perfect except one tell-tale detail: in Outlook, the messages arrived as "@supplier.com (from abcde.com)". Small, easy to miss — and missed it was. The client carried on the conversation exactly where it had left off.
The payment: even the bank's warning wasn't enough
Soon, an email arrived from the "supplier" with bank details for the £60k payment.
When the client went to pay, their bank flagged that the account details didn't match the payee. Alarm bells rang — so the client did what seemed sensible: they emailed the supplier to double-check, and asked for a phone number so they could confirm with a real person.
The problem, of course, was that they were emailing the attacker. Back came a UK mobile number. The client rang it and spoke to an American man who calmly explained the company had recently changed bank accounts and the records simply hadn't updated yet. Reassured, the client pushed through the bank's warning and sent the payment.
£60,000. Gone.
Why the usual defences didn't stop it
This attack succeeded because several gaps lined up at once.
The client's previous IT provider had left them on Microsoft 365 Business Standard, with no advanced email protection — nothing like Safe Links, which scans and rewrites URLs and could well have blocked the original phishing email. There was no monitoring for suspicious sign-ins, so a login from the other side of the Atlantic raised no flags. And because session hijacking bypasses MFA, even good password hygiene wouldn't have saved them.
At the time, session hijacking was still a relatively new technique. It was a hard lesson — for the client and for us.
What changed: how CyberBITS onboards clients now
That incident permanently changed how we work. Every client we onboard now gets these protections from day one:
Immediate session revocation. The very first thing we do when taking over a Microsoft 365 tenant is revoke every existing session and require every user to change their password. If an attacker is already sitting inside a mailbox with a stolen session cookie, this kicks them out on the spot.
Advanced sign-in monitoring with impossible travel detection. If you're happily logging into Microsoft 365 from your office in Cannock and moments later our logs catch a login to the same account from the US, we automatically block the account and reset the password before any damage is done.
Proper email security. Safe Links and layered phishing protection, so the malicious link that starts an attack like this is far more likely to be stopped before anyone can click it.
The proof: the next attack failed
Here's the part that matters most. Some time after the incident, the same client clicked another phishing link. People are human; it happens, even after a £60k lesson.
This time, our monitoring caught it immediately. The account was blocked, the credentials were reset, and the attacker got nothing. No hijacked session, no mailbox rules, no fraudulent invoice. The systems did their job — and the client lost nothing but a few minutes resetting a password.
Worried your business could fall for invoice fraud?
Business email compromise doesn't target careless people — it targets busy people, with attacks convincing enough to fool anyone. If your Microsoft 365 tenant has no advanced email protection, no sign-in monitoring, and no plan for session hijacking, you're relying on luck. Check out our Blog Post on this very subject.
Get in touch with CyberBITS to get your Microsoft 365 security reviewed — before someone else reads your email for you.