Over the past few months, small-business inboxes have quietly become a favourite target. We are no longer talking about the clumsy, typo-ridden emails of a few years ago: attackers now lean on artificial intelligence to write convincing messages and to work around two-factor authentication. Microsoft has reported a 146% rise in adversary-in-the-middle attacks over the past year, and Microsoft 365 accounts sit at the centre of the storm. For a company that runs its email, documents and approvals in the cloud, a single stolen sign-in can disrupt the whole operation.
Why smaller companies end up in the crosshairs
A comforting but dangerous belief still circulates: “we’re too small for anyone to bother with us.” The opposite is true. Firms with a handful of employees rarely have an in-house IT team, formal security policies or any real sign-in monitoring. For an attacker, that means an excellent effort-to-reward ratio.
- A single administrator often manages everything, so compromising one account opens many doors.
- Suppliers and clients trust email arriving from a familiar domain.
- Invoices and banking details move through mailboxes as a matter of routine.
The prize is not the size of the business; it is the web of trust that surrounds its digital identity.
How artificial intelligence rewrote the rules
The real shift of recent months lives here. Ready-made criminal platforms have appeared, sold on Telegram for a few hundred euros a month, that generate phishing text with AI, clone the templates of well-known brands and capture credentials in real time.
For the person receiving the message, the practical effect is unpleasant: almost every classic warning sign disappears. The tone is professional, the logo is right, the copy is fluent and tailored to the recipient’s industry. Automation also lets attackers launch thousands of personalised campaigns at once, something that previously demanded time and language skills. The low cost of these tools is the true engine behind the surge in attacks, not any single genius hacker.
Device code phishing, explained plainly
One of the sneakier techniques abuses a legitimate Microsoft feature: the authorisation flow built for devices like smart TVs and printers, where typing a password is awkward. Normally the system shows a code and asks you to enter it on microsoft.com to authorise the device.
The attacker flips this around. They send the victim a seemingly harmless code, perhaps disguised as a meeting invitation or the setup of a new device. The person enters it on Microsoft’s genuine site and completes authentication in good faith, MFA included. At that moment, though, they are not authorising their own device: they are handing access to the criminal’s. Technically the MFA is never “cracked”; it is simply turned against the very user who completes it.
Adversary-in-the-middle: when the second factor isn’t enough
The second fast-growing category is known as adversary-in-the-middle. The concept is to slip a server controlled by the attacker between the user and the real Microsoft login page.
The victim believes they are typing their credentials on the official portal, but the traffic passes through an invisible proxy that records everything: username, password and, above all, the session token issued after MFA. That token is the real loot. Holding it, the attacker walks in without repeating any verification, because as far as Microsoft is concerned the session is already authenticated. This is why relying on SMS codes or push notifications alone no longer offers the protection it once did: the extra factor is bypassed downstream, after the user has already completed it.
The signals your team should learn to read
Even though the messages have improved, some warning signs remain. They are worth sharing with everyone who touches email during the working day.
- Unexpected requests to enter a code, authorise a device or “reconfirm” access.
- Artificial urgency: instant deadlines, threats of account suspension, pushy language.
- Links that, when hovered over, point to domains slightly different from the official ones.
- QR codes received by email, increasingly used to move the scam onto a phone, where checks are weaker.
The rule of thumb: faced with any unsolicited authentication request, pause and verify through a different channel.
The technical defences that genuinely matter
The good news is that solid countermeasures exist and are within reach even for a small team. The point is not buying yet another piece of software, but properly configuring what Microsoft 365 already provides.
- Phishing-resistant MFA: passkeys and FIDO2 security keys are bound to the real site’s address and simply won’t work on a fraudulent proxy.
- Conditional Access: restricting sign-ins to compliant company devices or expected countries shrinks the attack surface.
- Device code flow control: disabling it where it isn’t needed closes a heavily abused door.
These settings need expertise to tune without disrupting daily work, but the security payoff is immediate.
Training and monitoring: the value of an IT partner
Technology on its own doesn’t close the loop. A modern attack targets people, so the defence has to start with whoever sits in front of the screen. Short, concrete training sessions, phishing simulations and clear rules on how to report a suspicious message are worth as much as a good configuration.
Monitoring belongs alongside it: spotting an unusual sign-in quickly, from an odd location or at a strange hour, lets you revoke sessions before the damage spreads. This is where an external IT partner earns its place for a small business, bringing skills and continuous attention that are hard to build in-house. Treating security as an ongoing process, rather than a one-off purchase, is what separates the companies that absorb the blow from those that are floored by it.
Want to know more? Contact us for a free consultation.