Executive Summary
- The MFA Vulnerability: A phishing technique called “session hijacking” or “adversary-in-the-middle phishing” bypasses multi-factor authentication by using a relay site to capture authenticated session tokens in real time.
- The Attack’s Execution: Once attackers steal the session token, it acts as a temporary all-access pass. They can access the user’s account directly without ever triggering a password guess or an MFA challenge.
- High Risk for Accounting: Accounting firms are attractive targets due to the trusted nature of their client communications and high volume of sensitive data, which can lead to major regulatory and professional exposure if breached.
- Necessary Defensive Layers: Relying solely on MFA is insufficient; firms must implement technical safeguards such as Conditional Access policies, shorter session lifetimes, rapid token revocation capabilities, mail rule audits, and sign-in behavior monitoring.
A newer phishing technique is bypassing multi-factor authentication without cracking a single password — and accounting firms are a natural target.
Ask most firm leaders about email security and the answer is usually the same: “We have MFA, we’re covered.” That assumption deserves a second look. A technique known as session hijacking, or adversary-in-the-middle phishing, is proving that MFA alone isn’t the safeguard many firms believe it to be — and firms handling client financial data, tax records, and sensitive correspondence are an especially attractive target.
Here’s how it works, based on a real incident our firm helped contain at a regional nonprofit client. The technique applies just as directly to accounting and tax practices.
How the Attack Works
An employee received an email directing her to what looked like a standard Microsoft 365 login page. She entered her credentials and completed multi-factor authentication exactly as she always did. Nothing appeared out of the ordinary.
But the page wasn’t the real login screen. It was a relay: a site positioned between the employee and Microsoft’s actual servers, capturing her credentials and MFA response in real time and passing them through to the legitimate service. In the process, it also captured something more valuable than a password — the authenticated session token created the moment her login succeeded.
That token is, in effect, a temporary all-access pass. Anyone holding it can act as the logged-in user without ever needing to present a password or complete an MFA challenge again. Days later, the attacker used that stolen session to log into the account directly. No password guess. No MFA prompt. To Microsoft’s systems, it looked like the same employee returning to her inbox.
From there, the attacker read mailbox contents, quietly created a mail rule to auto-delete incoming replies, and used the account to send hundreds of file-sharing invitations and emails to external contacts — all under the legitimate employee’s name and credibility.
Why This Matters for Accounting Firms Specifically
Firms operate on a foundation of trusted correspondence. Clients open attachments and click links from their accountant without hesitation, because that relationship is built on years of reliability. That trust is exactly what an attacker is exploiting when a compromised account starts distributing “invoice” or “document” links during already-hectic periods like tax season.
The professional and regulatory exposure compounds the risk. If a compromised mailbox contained client financial data — tax returns, banking details, payroll records — firms may face notification obligations, and clients may reasonably question the firm’s data-handling practices regardless of how the incident occurred.
What This Means for Firm Operations
Multi-factor authentication remains an essential control, but it was never designed to stop an attacker who steals the session created after authentication succeeds. Closing that gap requires additional layers:
- Conditional Access policies. Restrict sign-ins by expected location, device, and network, so an authenticated session from an unrecognized country or device is blocked or challenged, regardless of whether the credentials are valid.
- Shorter session lifetimes. Reducing how long a session token remains valid limits the window an attacker has to use a stolen one.
- Rapid session revocation capability. In an active incident, resetting a password is not sufficient on its own — active session tokens must be invalidated immediately to end an attacker’s access.
- Mail rule audits. Attackers frequently create rules named with punctuation marks so they render as blank or invisible in a quick review. Periodic audits of mailbox rules should specifically look for this pattern.
- Staff awareness training. Because the fake login page is often visually indistinguishable from the real one, training should focus on URL verification habits rather than relying on staff to “spot” a fake page by appearance.
- Incident response planning that accounts for session-based compromise. Firms should confirm their response plan explicitly addresses token revocation and mailbox forensic review, not just password resets.
A Note on Detection
One of the more sobering aspects of this attack pattern is how ordinary it looks from the inside. The employee in the incident referenced above did nothing wrong by any conventional measure — she used a device she always used, completed MFA as expected, and had no reason to suspect anything unusual. Detection depended entirely on monitoring for anomalies in sign-in behavior, not on any failure of judgment by the user.
That distinction matters for firm leadership. This is not primarily a training gap to be closed by telling staff to “be more careful.” It is a technical gap that requires the right configuration and monitoring layered on top of MFA.
The Takeaway
Session hijacking attacks are becoming more common precisely because they work around the defense most firms already consider sufficient. For firms managing sensitive client financial information under tight compliance expectations, reviewing whether Conditional Access policies, session lifetime settings, and rapid revocation capabilities are in place is no longer optional diligence — it is a baseline expectation of client data stewardship.
==
Scott Carr, owner of Farmhouse Networking in Grants Pass, Oregon, is a veteran Network & Computer Systems Architect with over 30 years of IT experience. For over a decade, he’s led his team in delivering proactive, secure, and fully managed IT services to more than 80 businesses—including accounting and finance firms that rely on data security, compliance, and efficiency. Scott’s hands-on, jargon-free approach ensures every client understands their technology and gains confidence in their systems. His firm is known for fast, responsive support—most issues are resolved within 15 minutes—and deep expertise in cybersecurity, network design, and IT compliance. Learn more about how Farmhouse Networking supports the accounting industry at https://www.farmhousenetworking.com/finance-it-support/.
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register Now Already registered? Click here to Log In