🕵️Post-authentication session theft (AiTM)
Rather than stealing a password, this technique intercepts the session right after the victim validates their two-factor code — the attacker positions themselves as an invisible intermediary between the victim and the real service. The result: two-factor authentication did happen, but it accomplished nothing. In October 2025 alone, Microsoft blocked more than 13 million malicious emails linked to a single one of these kits ("Tycoon 2FA"), used against Microsoft 365 accounts worldwide.
Microsoft Defender for Office 365, October 2025☎️Telephone-oriented attack delivery (TOAD) phishing
An email with no link or attachment: just a number to call back about a suspicious invoice or a subscription to confirm. With no URL to scan or file to analyze, classic automated filters catch nothing — the scam plays out entirely on the phone, where a fake advisor walks the victim through installing remote-access software or handing over credentials. Research firm Trustwave measured a 140% rise in these campaigns between July and September 2024, with Microsoft, Norton, PayPal and DocuSign among the most impersonated brands.
Trustwave, 2024-2025The common thread: bypassing automation, not attention
Neither technique exploits a technical flaw in the classic sense — they exploit a structural limit of automated detection tools, by removing the very element those tools know how to analyze (a link, an attachment). What's left is a human interaction built to look legitimate: a login page identical to the real one, or a reassuring voice on the phone. That's exactly the kind of pattern a multi-channel protection needs to learn to recognize rather than scan.
Frequently asked questions
Does two-factor authentication still protect against phishing?
It's still useful against simple password theft, but not against an "adversary-in-the-middle" attack: the attacker intercepts the session right after the victim validates their code, so two-factor authentication has already happened — uselessly.
What is telephone-oriented attack delivery (TOAD) phishing?
An email with no link or attachment, just a phone number to call back for a credible reason (an invoice, a subscription). Once on the phone, a fake advisor walks the victim through installing software or handing over credentials.
Why do these techniques slip past automated filters?
Because they often contain neither a suspicious link nor a malicious attachment to scan — the scam plays out in human interaction, on the phone or on a page that perfectly mimics the real one.
Other markets we cover
These techniques don't respect borders — national cyber agencies and researchers document the same AiTM and callback mechanisms hitting other markets, with their own numbers.
🇦🇺Australia — attackers pivot beyond AiTM to dodge defenses
ASD publicly warned Microsoft 365 users in May 2026 about "device code phishing" — a technique researchers say the operators behind the AiTM kit Tycoon 2FA began selling after a February 2026 disruption to their infrastructure. ASD said it had received multiple reports of Australian users being actively targeted.
Australian Signals Directorate, public advisory, May 2026; Proofpoint research.🇬🇧United Kingdom — one kit's reach grew from 184 to 290 targets in three weeks
UK researchers tracked an AiTM phishing kit first detected on 27 February 2025, hitting mostly construction, manufacturing, engineering and energy firms in the UK. It used lookalike pages mimicking Adobe and Gamma App, with tracked instances growing from 184 to 290 in under a month.
JUMPSEC, "UK Industrial Sector AiTM Phishing Campaign," March 2025.🇨🇦Canada — 100+ AiTM campaigns against one sign-in system alone
Canada's national cyber centre detected more than 100 distinct AiTM campaigns targeting Canadian organizations' Microsoft Entra sign-in systems between 2023 and early 2025. Separately, Microsoft documented "Storm-2755," a campaign that hijacks Microsoft 365 sessions specifically to redirect Canadian employees' salary deposits.
Canadian Centre for Cyber Security, ITSM.30.031, 2025; Microsoft Threat Intelligence.🇮🇳India — credential theft overtakes hacking as the way in
The Digital Threat Report 2025–26, a joint effort of India's CERT-In, the financial-sector CSIRT-Fin and forensics firm SISA, found that credential theft and session hijacking — the mechanism behind AiTM phishing — have become the primary way attackers gain initial access to the country's financial systems, alongside an intensified wave of Business Email Compromise.
CERT-In, CSIRT-Fin & SISA, Digital Threat Report 2025–26, July 2026.Go further
Egidio — The Threat Laboratory, "Emerging phishing techniques: when antivirus isn't enough anymore", egidio.app/en/laboratoire/emerging-phishing-techniques/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.