An email arrives from a supplier, colleague or customer you know. The address is familiar. The signature looks right. There is a document to review and a button to open it. Would you pause before signing in?

In a business email compromise investigated by Primeworks, an unauthorised party used a staff member’s Microsoft 365 mailbox to send malicious messages. Identifying details have been removed. The initial entry method was not conclusively established; the session-theft explanation below describes a known attack technique.
How a signed-in session can be stolen
After you sign in, your browser receives a temporary digital pass, often called a session cookie, which lets you continue working without signing in on every page.
Some phishing websites secretly relay the real Microsoft sign-in process. You enter your password and complete an MFA check, but the attacker captures the authenticated session. They may then reuse that session to access your account without another approval prompt. This is one form of token theft.
MFA remains essential. However, a genuine MFA prompt does not prove that the link you followed was safe. The extra check can be completed during a sign-in that began on a phishing website.
Part 1: Reduce the chance of account compromise
- Verify unexpected documents before signing in. Ask whether the sender intended to share the file. Open Microsoft 365 through your usual app or saved bookmark. Genuine shared files sometimes require a sign-in; an unexpected request is a reason to check first.
- Use stronger sign-in protection. Keep MFA enabled and ask IT about phishing-resistant methods such as passkeys or security keys. These help prevent fake websites from relaying your sign-in. Never share verification codes or approve unexpected prompts.
- Protect the devices used for work. Keep browsers and devices updated, retain endpoint protection and avoid unapproved software or extensions. Malware can also steal sessions, so stronger sign-in methods still need secure devices.
- Ask IT to enforce access controls and monitoring. Depending on your environment, this can include requiring approved, compliant devices, filtering harmful links and monitoring unfamiliar sign-ins, new authentication methods, suspicious mailbox rules and unusual sending.
Passkeys and security keys, in plain language
A passkey is a digital sign-in credential you unlock with your fingerprint, face or device PIN. It works only with the legitimate service it was created for, helping protect you from fake sign-in pages. A FIDO2 security key is a small physical device that can hold a passkey. Many people can use a compatible phone without buying a key. Ask IT to set up the right option and a recovery method. Passkeys protect the sign-in process; they do not replace device protection.
Part 2: Recognise phishing from a familiar account
A criminal inside a mailbox may copy its signature, read earlier conversations and reply within a genuine email thread. Even a link to a real file-sharing service can lead onwards to a phishing page. Judge the request in context, as well as checking the address.
| What you notice | Why you should pause |
|---|---|
| An unexpected document with little explanation | A vague “please review” message gives you little to check against your actual work. |
| A document link asks for your password or MFA approval | The sign-in may be what the attacker wants. Verify the sharing request first. |
| The website address looks unfamiliar, or the link sends you through other sites | The destination may differ from the service the message claims to use. |
| Pressure to act immediately or bypass normal checks | Urgency discourages you from checking with someone else. |
| A familiar conversation suddenly changes direction | New bank details, an unusual attachment or an unexpected sign-in request can signal a takeover. |
These are reasons to verify, not proof on their own. Correct spelling, familiar branding and the absence of an email warning do not establish that a message is safe.
Already clicked or signed in?
Stop interacting with the message and contact IT immediately. Explain whether you only opened a link, entered a password, approved MFA, downloaded a file or ran anything. Do not wait for obvious damage or feel embarrassed about reporting it.
Changing a password alone may not be enough. IT may also need to revoke active sessions, investigate the device and check authentication methods, mailbox rules and other account changes.
How Primeworks helps
Primeworks helps businesses strengthen Microsoft 365 security, improve email protection and respond to suspicious activity. Existing clients should use their known support route: support@primeworks.co.za or 011 887 3900.
Related reading: Security Brief #003: Unexpected MFA Prompts — Don’t Approve the Attack.
Sources and further reading
- Microsoft: How phishing sites steal session cookies
- Microsoft: Compromised accounts spreading phishing through trusted relationships
- Microsoft Entra: Protecting tokens and reducing theft risk
- Microsoft: Phishing-resistant MFA
- Microsoft: Recognising and reporting phishing
- Microsoft: Passkeys and security keys explained