Sales: (651) 415-2266 Service: (651) 482-8718

Security

Your Microsoft 365 MFA Is Not Enough: What September 2026 Taught Every SMB.

By 5 min read

Your Microsoft 365 MFA Is Not Enough: What September 2026 Taught Every SMB

Most small and mid-sized businesses turned on multi-factor authentication for Microsoft 365 and considered the job done. That assumption took a serious hit in September 2026. A wave of attacks targeting Microsoft 365 accounts bypassed MFA entirely, and on September 22, Microsoft's Digital Crimes Unit shut down a phishing-as-a-service platform called EvilTokens after it compromised more than 12,000 inboxes across over 10,000 organizations worldwide.

What Happened

EvilTokens was a phishing-as-a-service platform that let criminals rent ready-made attack kits, complete with an AI chatbot assistant, to steal authentication tokens from Microsoft 365 accounts without ever needing a victim's password. The takedown, backed by a federal court order out of the Eastern District of Virginia, seized 50 websites and disabled more than 150 supporting domains. But the platform ran for seven months before it was stopped.

EvilTokens was one part of a broader September pattern. Microsoft published research on September 9 warning that threat actors linked to ShinyHunters, Helix, and other extortion groups were running passkey-themed social engineering campaigns against corporate Microsoft 365 accounts. Separately, security firm Arctic Wolf documented a campaign where attackers posed as IT help desk staff in phone calls, walked employees through what sounded like a routine MFA setup, and walked away with full access to email, SharePoint, OneDrive, and Teams.

Why MFA Alone Does Not Stop This

These attacks work because they do not try to break MFA. They let you complete it. Here is the short version of how adversary-in-the-middle phishing works: the attacker puts a proxy between you and the real Microsoft login page. You see a legitimate-looking sign-in screen, enter your credentials, and complete your MFA challenge exactly as you normally would. At the moment Microsoft issues a session token confirming your completed authentication, the proxy intercepts that token before it reaches your browser. The attacker now holds a valid, authenticated session. They can open your Outlook, Teams, and SharePoint without entering any credentials and without triggering any further MFA prompts.

Device code phishing works differently but lands in the same place. The attacker tricks a user into entering a short code into Microsoft's own legitimate authentication page. That action issues an authentication token directly to an attacker-controlled application. After gaining access, attackers often lock in their foothold by registering new phone numbers and authenticator apps under the compromised identity, so they can satisfy future MFA challenges without the victim's help.

The social engineering piece makes this particularly dangerous for smaller organizations. Attackers impersonate IT support, contact employees directly by phone, and reference plausible-sounding tasks such as updating a passkey or reconfiguring single sign-on. The word passkey arrives pre-loaded with trust because the security industry has spent years promoting it as the gold standard. Attackers borrowed that vocabulary and used it against the people who heard it.

Why This Matters to Your Business

Microsoft 365 is the operating system of most small businesses today. Email, file storage, calendars, video calls, and often accounting or CRM integrations all run through it. A single compromised account can expose every file that account can access, enable internal phishing against your coworkers or clients, redirect payments, and give an attacker a persistent foothold that may go undetected for weeks. SMB cyber incidents now cost businesses an average of $120,000 to $1.24 million per attack, and downtime from a serious breach can last five to twenty-one days.

These campaigns specifically targeted US organizations and Microsoft 365 users through September. Your business does not need to be a high-profile target. Attackers using phishing-as-a-service platforms operate at scale. They pursue hundreds of organizations at once and move on quickly to whichever ones respond. The barrier to launching a sophisticated attack is now low enough that any employee with a Microsoft 365 account is a viable target.

Practical Steps to Take Now

1. Move to phishing-resistant MFA. Standard push notifications, number matching, and time-based one-time codes do not stop adversary-in-the-middle attacks. FIDO2 security keys and passkeys tied to your hardware are the controls that actually resist token theft at the authentication layer. Work with your IT provider to prioritize these for admin accounts first, then roll out to all users.

2. Configure Conditional Access policies in Microsoft Entra ID. Conditional Access can require that a session come from a compliant, managed device and from an expected location before it grants access. A stolen token replayed from an attacker's infrastructure in another country should trigger a block, not a green light. Most small businesses have not configured these policies because they require expertise to set up correctly.

3. Restrict device code authentication flow. Unless your business has a specific operational need for it, device code authentication should be blocked through a Conditional Access policy. This eliminates one of the two primary techniques attackers used throughout September.

4. Train employees on IT impersonation calls. Your IT provider, including any outsourced help desk, should have a clear and documented verification procedure before any employee takes action on an unexpected phone call. Teach your team that a caller asking them to enter a code anywhere is a red flag, regardless of how official the request sounds.

5. Review SharePoint and OneDrive sharing permissions. Once inside an account, attackers map out what data is accessible. Tighten sharing settings so that sensitive files are not broadly available to every account in your tenant. Least-privilege access limits the blast radius of any single compromised account.

6. Enable unified audit logging and set up alerts for suspicious sign-in activity. Token theft from an unexpected location or an unusual application should generate an alert your team actually sees. Many SMBs have logging turned off or have no one reviewing it. Detection speed directly determines how much damage a breach can do.

The Bigger Picture

The EvilTokens takedown is good news, but it is not a signal to relax. Phishing-as-a-service platforms get replaced. The techniques EvilTokens industrialized are documented, copied, and already in use by other actors. MFA remains worth having. It stops a large category of attacks. But treating it as a complete solution is now a dangerous position. The threat moved, and your defenses need to move with it.

Talk to Gryphon Tech Advisors

If you are not sure whether your Microsoft 365 environment is configured to block session token attacks, Gryphon Tech Advisors can assess your current posture and close the gaps. We work with small and mid-sized businesses across the Plymouth and greater Minneapolis area every day. Reach out to our team at gryphonitadvisors.com or call us directly to schedule a security review.

Next step

Make your next technology decision with better information.

Talk with an advisor about your current environment, risk, support model, and business priorities.

Start a conversation