InsightPhishingIdentity securityBEC

The next phishing wave is not just email. It is identity-led, Microsoft 365-aware and built around finance and supplier workflows.

Attackers increasingly want session tokens, OAuth consent, mailbox access and trusted payment threads, not just passwords. That changes the defence.

Email filtering and awareness training still matter, but they are no longer the centre of the control stack. The work now sits in Conditional Access, phishing-resistant MFA for sensitive roles, OAuth consent governance, mailbox monitoring, DMARC enforcement, device compliance and finance-workflow verification.

Inbox / identity / payment workflow
ATTACK INBOXCONSENTMAILBOXPOLICY Email and InboxOAuth ConsentMailbox AccessConditional Accessphishing-resistant MFAPayment RedirectBEC fraudPHISHPHISHPHISHPHISHPHISH FINANCE WORKFLOW
AttackIdentity-first attack patterns
ConsentOAuth and Conditional Access
MailboxCompromise and BEC sequencing
FinanceWorkflow control hardening
Quick orientation

Three questions that clarify where phishing has actually moved

What identity-led phishing means, why MFA alone is no longer enough, and how modern BEC actually works.

01

What does identity-led phishing actually mean?

Techniques that target access tokens, OAuth app consent, or active sessions rather than passwords — device code phishing, adversary-in-the-middle (AiTM) kits, and malicious app consent. These methods can bypass standard MFA because they capture the session itself or trick the user into authorising the attacker's app, rather than stealing a password typed into a fake login page.

ThemeAttack surface
02

Why is MFA alone no longer enough?

Phishing-resistant MFA — FIDO2 security keys, certificate-based authentication — materially reduces risk. SMS, voice and basic push-notification MFA can still be intercepted by AiTM kits or bypassed by device code phishing. For sensitive roles, the control quality matters more than the presence of MFA. The Australian Signals Directorate now explicitly recommends phishing-resistant MFA for high-risk users and online services.

ThemeControl quality
03

How does modern BEC actually work?

Modern BEC often begins after mailbox access is gained, not before it. The attacker silently observes live conversations, sets hidden inbox rules, watches payment threads, and uses the real account at the right moment to redirect funds. The instruction looks legitimate because it comes from the real address and references real conversations. Spam filters do not catch this — the defence sits in identity controls, mailbox monitoring and finance-workflow verification.

ThemeBEC sequence
What changed

The next phishing wave is identity-first, not inbox-first.

Inbox-led phishing
  • Targets the password
  • Caught by filtering and training
  • Question: are users clicking?
  • Defence spam filter and awareness
Identity-led phishing
  • Targets tokens, consent and sessions
  • Built to work around standard MFA
  • Question: when a user clicks, what does the stack catch?
  • Defence identity policy, consent governance, mailbox visibility, DMARC, finance verification
What attackers are running

Six techniques shaping how phishing actually lands.

None of these should be treated as nation-state-only techniques. All are now relevant to SME and mid-market Microsoft 365 environments — some visible in Australian threat reporting at category level, others in current global Microsoft and threat research that closely reflects how Australian organisations operate.

Technique 01 · Device code phishing
How it landsUser is sent to a Microsoft-branded device-code activation page with a real code from a real attacker session. They authenticate normally. The attacker now holds the session token without ever needing the password.
The controlBlock device code flow via Conditional Access.
Technique 02 · Adversary-in-the-middle (AiTM) kits
How it landsA reverse-proxy phishing site captures both credential and session token in real time. Even MFA prompts are captured and replayed. SMS and basic push MFA do not stop this.
The controlPhishing-resistant MFA (FIDO2) for sensitive roles.
Technique 03 · Malicious OAuth consent
How it landsUser receives a request to authorise an application. They click “accept.” The attacker now holds persistent access to mail and files without ever revealing a password. Password resets do not remediate this.
The controlRestrict who can grant consent; review consented apps.
Technique 04 · Internal-looking spoofs
How it landsPhishing actors exploit complex routing and configuration weaknesses to make messages appear to be sent from inside the organisation. Standard tenant trust is the lure. Familiar faces in the From line.
The controlStrict DMARC enforcement and tenant authentication policy.
Technique 05 · QR code and mobile lures
How it landsPhishing email contains a QR code that resolves on a personal mobile device, outside the controlled browser stack. Credential capture happens on the unmanaged device. Email security never sees the click.
The controlDevice compliance enforcement and Conditional Access.
Technique 06 · Out-of-band approaches
How it landsPhishing arrives via SMS, WhatsApp, Signal or voice, often as a follow-up to legitimate-seeming email. The lure is timing and impersonation, often of a known supplier or executive.
The controlOut-of-band verification on payment and supplier changes.

The Australian threat data sits where the work sits. In FY2024-25, the Australian Signals Directorate's Cyber Security Centre recorded email compromise without financial loss as the top self-reported cybercrime threat category for businesses at 19%, and BEC causing financial loss at 11% (Australian Signals Directorate, Annual Cyber Threat Report 2024-25). The threat is concentrated where business operations concentrate. The defence has to sit there too.

Structural exposure signs

A tenant can have MFA, EDR and a reasonable spam filter, and still be exposed to every technique above.

The visible posture and the operational posture are not the same thing. None of these exposures require advanced threat actors — all are exploited at SME and mid-market scale every week in Australia. What is needed is engineering ownership of the configuration and the alerts.

Identity and access
01

Broad app consent

Users can broadly consent to third-party cloud apps without admin review.

02

Device code flow never reviewed

Device code authentication flow is enabled tenant-wide and never reviewed.

03

High-risk users, standard MFA

Admins, finance and executives have the same MFA quality as everyone else.

04

Risky sign-ins uninvestigated

Sign-ins from unfamiliar geographies or impossible-travel patterns do not trigger investigation.

Mail, devices and workflow
05

Payment changes from email alone

Finance and supplier banking changes can be approved from email alone.

06

DMARC configured, not enforced

SPF, DKIM and DMARC are configured but not enforced at strict policy level.

07

Mailbox alerts unmonitored

Inbox-rule and mail-forwarding alerts are not monitored or triaged.

08

Personal devices fully trusted

Personal devices access Microsoft 365 with the same trust as managed devices.

The five-step sequence

Most damaging BEC engagements do not start in finance. They start with mailbox access on someone nearby.

The compromise that ends in a redirected payment is rarely the first event. It is the result of a sequence the attacker runs over days or weeks, often through a mailbox that does not feel high-risk on the org chart — a project lead, EA or sales contact with broad supplier visibility.

Spam filters do not catch step four. The email is genuine — it comes from the real address, references real conversations, and arrives at the right moment in the workflow. The protection has to come from identity-side detection at step one, mailbox monitoring that surfaces the hidden rule at step two, and finance workflow rules that do not allow payment-detail changes from email alone at step four.

How modern BEC unfolds
01Mailbox access gained
02Hidden inbox rule set
03Payment thread observed
04Real account sends new details
05Payment processed
What the control stack looks like

Modern phishing defence is not one product. It is eight controls operating together.

Each control below is an operational layer. None replaces the others. The combination is what reduces real risk for an SME or mid-market Microsoft 365 environment.

Many of these can be improved inside the Microsoft 365 controls organisations already own, although licensing and monitoring requirements vary. If finance can change supplier banking details from email alone, the BEC problem exists before the first phish lands — process discipline is part of cyber defence, not separate from it.

Operate
Phishing-resistant MFA for sensitive roles
FIDO2 keys or certificate-based authentication for admins, finance, executives and remote access.
Conditional Access for risky flows
Block or restrict device code flow, legacy authentication and unfamiliar geographies.
OAuth consent governance
Restrict who can grant consent; review apps; a revocation playbook beyond password resets.
Email authentication enforcement
SPF, DKIM and DMARC enforced at strict policy level; spoofs rejected, not junked.
Mailbox visibility and detection
Forwarding rules, inbox manipulation, re-registrations and consent grants surfaced and triaged.
Workflow and finance verification
Payment changes verified by phone on a known number, never the number in the email.
Device compliance enforcement
Unmanaged devices do not get the same trust as managed endpoints.
Response that includes mailbox investigation
Rules, forwarding, sent items, app consent and MFA changes checked — not just a password reset.
The Inlight IT view

Phishing defence now needs engineering ownership across Microsoft 365.

The Inlight IT view is that phishing defence now needs engineering ownership across Microsoft 365, not just user reminders and email filtering. Conditional Access needs to restrict risky flows. Sensitive roles need stronger MFA. App consent needs governance. DMARC needs enforcement. Mailbox forwarding and inbox-rule changes need monitoring. Personal-device access needs policy. Finance teams need a controlled process for payment and supplier banking changes. A useful review tests the controls attackers now work around — the work is engineering ownership of the configuration and the alerts, not a poster campaign.

If finance can change supplier banking details from email alone, the BEC problem exists before the first phish lands.

01

Restrict risky authentication flows

02

Strengthen MFA for sensitive roles

03

Govern consent and enforce DMARC

04

Monitor mailboxes and verify payment changes

Cyber Security Review

Make phishing defence an operating control, not a reminder campaign.

Review identity, email and payment-change controls before phishing becomes operational exposure.

Discuss your cyber security position