Wealth management

MFA didn't stop it. Find out who clicks before an attacker does.

A phishing service called BigBear 2.0 walked straight through multi-factor authentication at 258 organizations this month.

1 min readOriginally posted on LinkedIn

A phishing service called BigBear 2.0 walked straight through multi-factor authentication at 258 organizations this month — and the people who fell for it did everything right.

Here's the trick. The fake Microsoft sign-in page wasn't a copy. It was a live relay sitting between the employee and the real Microsoft login. They typed their password. They approved the MFA prompt. It all worked, because it was the real login, just passed along. What the attacker kept was the session cookie — the digital version of the wristband you get after the bouncer checks your ID. Researchers counted 4,148 of those stolen.

For a wealth management firm, that means someone quietly reading a client's email thread about a pending transfer, then writing the next message in it. The recovery isn't technical. It's the phone call you make to that client.

You can't train your way out of every attack, but you can find out who clicks before a stranger does. Microsoft's Attack Simulation Training sends your own team a realistic fake — credential page, QR code, malicious app consent — and reports back who opened it, who typed a password, and who reported it. It's included with Microsoft 365 E5 and Defender for Office 365 Plan 2.

Worth running one before your next cyber renewal. The results are humbling, and that's the point.

ShareLinkedInEmail

Want the next one in your inbox?

One practical Microsoft 365, Copilot, Azure, or security move per week — plain English, no pitch.

Subscribe via email

All editions