The Tool That Steals Your Microsoft 365 Login Rents For $320/Month
.png?width=1200&height=630&name=IMAGES-4%20(17).png)
Here is what these tools take. When you sign in, prove who you are, and approve the prompt on your phone, Microsoft hands your browser a token that keeps you signed in for the rest of the day. It is proof the whole process already happened. Someone who copies it needs neither your password nor your phone, because they are not signing in. They are already inside.
These are sold as phishing kits, and one of them was reported against more than three thousand five hundred organizations this month. A second rents by the month, with support, the way ordinary software is sold.
The delivery worth picturing is the kind that does not look like an attack. Counterfeit QR stickers have been turning up on restaurant tables, placed over the real ones, and scanning one returns a genuine copy of the menu. Nothing seems wrong. Follow any link on that page and you are asked to sign in to Microsoft 365, on a page Microsoft did not build.
A related version never asks for a password at all. It asks you to type a short number into a real Microsoft authorization page, which is why nothing looks suspicious. The page is genuine. Typing the number surrenders the account.
So the guidance most businesses were given three years ago has quietly stopped covering this. Turning on the code from a text or an app was worth doing and still is, because it ended password guessing. It does nothing here. The attacker waits until after you enter the code and takes what the code produced.
What works is a different kind of sign-in rather than a stronger version of the same one. A security key, or a passkey held in the device hardware itself, ties your login to that one device and that one website. A copy taken anywhere else is worthless.
Two things to ask for, and neither is a project. First, the hardware-backed kind. A passkey stored inside a password manager can be copied out of that account, so it is easy to buy the word without the protection. Second, the authorisation method those number-typing attacks depend on can be switched off for anyone who does not need it, which is nearly everyone.
And if you take one thing: changing the password does not end the session. It never was the password.
NexusTek is a CMMC L2-certified managed service provider serving small and mid-sized businesses across the United States.
