If you're an IT admin who deployed MFA and figured business email compromise (BEC) was a solved problem, there's an active campaign right now proving otherwise.
According to The Hacker News, attackers are running a US-focused phishing campaign that specifically targets C-suite executives, steals authenticated Microsoft 365 sessions, and then deploys RMM tools to maintain remote access. The important detail: this attack doesn't need your password, and it doesn't need to beat your MFA prompt. It steals the session token after authentication has already happened, which means MFA — the control most small businesses lean on hardest — never gets a chance to stop it.
This is exactly the gap raised in the Reddit threads that inspired this post: teams running ITDR tools still got hit with BEC, and Microsoft has quietly shifted MFA registration behavior without much warning. The tools were in place. The breach still happened. So what actually would have caught it?
Why MFA Alone Isn't Enough Anymore
MFA is designed to stop credential theft — someone guessing or phishing your password. It was never designed to stop session hijacking, where an attacker steals the cookie or token generated after you've already logged in and passed MFA. Once that token is stolen, the attacker looks like you to Microsoft 365. No second prompt required.
We've written before about how device code phishing bypasses MFA in a similar way — tricking users into approving a legitimate-looking auth flow that hands over a valid session. Session-token theft campaigns are just the next evolution of the same core problem: MFA protects the login, not everything that happens after.
Where ITDR Fits — and Where It Falls Short
Identity Threat Detection and Response (ITDR) tools are supposed to catch anomalous identity behavior: impossible travel logins, new device fingerprints, unusual mailbox rule creation, or a session suddenly being used from a different geography. In theory, ITDR is exactly the layer that should catch a stolen session in use.
In practice, according to the same Reddit discussion referenced in this post, two separate BEC incidents went completely undetected despite ITDR being deployed. That's not a knock on ITDR as a category — it's a reminder that ITDR is a detection layer, not a prevention layer. It has to be tuned, monitored, and alerted on by a human who actually acts on the alert. A tool sitting quietly in a dashboard that nobody checks is functionally the same as no tool at all.
That undetected-for-weeks pattern isn't unique to small business M365 environments either. According to The Hacker News, a credential-based data theft incident against French tax systems using stolen staff passwords went undetected for seven weeks — in an environment that presumably had some level of monitoring in place. Detection tools only work if someone is watching the output and knows what to do with it.
Where Conditional Access Actually Closes the Gap
This is where Conditional Access earns its place. Unlike ITDR, which mostly detects and alerts, Conditional Access can actively block based on conditions: device compliance, location, sign-in risk level, and session lifetime. Set correctly, Conditional Access policies can force re-authentication on risky sign-ins, restrict access to managed devices only, and shorten how long a stolen session token is actually useful before it expires.
If you haven't reviewed your Conditional Access setup recently, our guide on Conditional Access policy setup order for small businesses walks through the sequence that actually matters — location-based restrictions and device compliance first, then risk-based sign-in policies, then session controls. Order matters because misconfigured policies can lock out legitimate users or leave gaps attackers exploit.
The Real Answer: Layers, Not a Single Tool
None of these controls alone stops the campaign described above. MFA stops credential theft but not session hijacking. ITDR can detect the hijack — if it's monitored and tuned. Conditional Access can limit the blast radius by restricting where and how sessions are used. Together, they cover more of the attack chain than any single control.
If your M365 environment has had login anomalies lately, it's also worth reviewing our broader breakdown of Microsoft 365 login attacks and the controls that actually stop them — it covers additional configuration steps beyond what's in this post.
Take Action
The uncomfortable truth is that most small businesses find out their identity controls have gaps only after an incident, not before. Proactive scanning catches misconfigurations, exposed sessions, and weak Conditional Access policies before an attacker does. Oscar Six Security's Radar scan is a $99 way to get a clear picture of where your identity and email security actually stand — no long contracts, no enterprise sales cycle. Check it out at our solutions page.
Focus Forward. We've Got Your Six.