Office Proofed
Risk at Work

What Actually Happens After One Employee Clicks a Fake Microsoft 365 Login Page

What Actually Happens After One Employee Clicks a Fake Microsoft 365 Login Page
A practical walkthrough of what really happens after an employee submits credentials to a fake Microsoft 365 login page: credential capture, silent mailbox access, forwarding rules, invoice fraud attempts, the cleanup sequence, and the prevention habits that stop the chain early. Written from Grant Dorsey’s first-person incident-response experience with small U.S. offices.

The most useful office phishing prevention tips I can share are less about spotting the fake login page and more about understanding what follows a successful click. In more than a decade of managing endpoints and cleaning up incidents for small companies around Madison, I have walked through this sequence often enough that a version of it sits in my “Avoidable Problems” notebook. Here is the part that surprises most owners: the click is rarely where the damage happens. The damage happens in the quiet hours afterward, when the mailbox quietly starts working for someone else.

The First Thirty Seconds After the Click

A fake Microsoft 365 login page does not need to look convincing to someone who is tired and rushed; it only needs to arrive at the right moment. The moment an employee types a real username and password into that page, the attacker receives those credentials immediately. There is no dramatic alert, no lockout, no pause. From your side, everything looks normal. From the attacker’s side, the door is open.

What the Fake Page Actually Captures

The page usually records more than a password. It often captures the full email address, the password, and, depending on how the kit is built, a session token or a one-time passcode. That last piece matters because a stolen session token can let an attacker into the mailbox even when multifactor authentication is switched on. I have watched teams breathe a sigh of relief over MFA, only to discover the phish succeeded after an employee approved a push notification they did not recognize on their own phone.

Why Everything Stays Quiet at First

Attackers rarely do anything loud in the first hour. They sign in from an unfamiliar location, confirm the account still works, and look for obvious value: unread mail from a bank, open threads with clients, anything containing the words invoice or wire. That quiet period, spent studying how your office talks to the people it pays, is what makes a single phish expensive.

close-up of an employee hand hovering over a spoofed Microsoft 365 login prompt on an office laptop

What the Attacker Does Inside the Mailbox

Once inside, the attacker treats the mailbox like a staging area, and this is the stage where most of my office phishing prevention tips actually matter. The mailbox gets searched, rules get created, and the account quietly becomes a relay for the next attack. None of this shows up in the antivirus console, because none of it is malware. It is just an authorized user doing authorized things with credentials you no longer control.

Forwarding Rules Go Up First

In the majority of incidents I have reviewed, a forwarding rule appears within the first hour. The rule forwards incoming mail that mentions invoices, payments, or your company name to an external address the attacker controls. Many attackers add a companion rule that deletes those forwarded messages from the inbox, so the employee never sees their own mail being copied out. I have audited mailboxes where forwarding ran for weeks before anyone noticed, because every message arrived and vanished exactly on schedule.

The Search for Money Movement

With forwarding in place, the attacker searches the mailbox for vendor names, past invoices, banking details, and payment instructions. In one case I worked through with a small manufacturing shop outside Madison, the attacker pulled up a real invoice from a real vendor, changed nothing but the bank account number, and sent it back to the bookkeeper inside the vendor’s actual email thread. The bookkeeper paid it without a second thought. Nothing about the email looked like an attack, because the email came from a conversation the office already trusted.

A realistic timeline of attacker activity usually looks like this:

  1. The credentials arrive at the attacker’s server within seconds of the employee pressing Enter.

  2. The attacker signs in from another location, usually within minutes.

  3. A mailbox forwarding rule appears in the first hour.

  4. Searches target invoice, payment, password, and the names of frequent vendors.

  5. Messages are drafted inside existing threads to keep the conversation looking legitimate.

IT administrator reviewing suspicious mailbox forwarding rules in the Microsoft 365 admin console after a phishing incident

When the Phish Turns Into an Invoice Fraud Attempt

This is where a stolen password becomes a cash problem. The invoice fraud attempt does not arrive from a stranger with a misspelled domain. It arrives from a vendor the office already trusts, using the same formatting, the same signatures, and the same email thread the office has been reading for years.

The Conversation Nobody Questions

The attacker studies the thread, learns how your office talks to the vendor, and then sends a polite note about updated banking details. It is short, professional, and free of manufactured urgency, which is exactly why it passes. By the time the real vendor asks why the last invoice went unpaid, the money has been sitting in the attacker’s account for weeks and the trail has gone cold.

What a Good Office Catches Early

The offices that catch this early usually share one habit: they confirm any change to payment details by phone, using a number already on file rather than one from the email. That habit costs twenty seconds and quietly stops the single most common invoice fraud route I encounter. It is not glamorous. It works.

The Cleanup That Follows

Once you realize the account was taken over, the real work begins. The cleanup follows a sequence, and skipping steps means the attacker keeps a way back in:

  1. Revoke the session and force the employee to sign out on every device.

  2. Reset the password and require fresh multifactor enrollment.

  3. Review and remove every forwarding rule, inbox rule, and delegate permission on the account.

  4. Search the sent folder and deleted items for replies the employee never wrote.

  5. Change the password on any other account that reused the same credentials.

  6. Tell the clients, vendors, and team members who may have received mail from the compromised account.

The Step Most Offices Rush

The step people rush is the last one. Notifying everyone who was contacted is awkward, so it gets postponed, and postponement is what turns a contained incident into a string of follow-on scams at the vendor’s office, the client’s office, and inside your own team.

The Prevention Lessons I Keep Coming Back To

After you clean up a few of these, the pattern becomes familiar. A lot of office phishing prevention tips focus on the moment of the click — spot the odd page, hover the link — but in my experience the moment that decides the outcome comes afterward, when you control how quickly the mailbox gets locked down and reviewed. The strongest defenses are ordinary, repeatable cybersecurity habits for employees rather than new software. Here is what I keep coming back to:

  • A review of recent sign-ins and forwarding rules every few weeks, not once a year.

  • A short phone-based confirmation step for any change to banking or payment details.

  • Multifactor authentication everywhere, with employees trained to deny prompts they did not trigger.

  • A clear internal rule that nobody changes payment instructions by email alone.

The realistic goal is not to make phishing impossible. It is to make the chain break early, before the mailbox becomes a tool for invoice fraud. Security gets easier when the rules make sense, and this is one place where a single simple habit — confirm payment changes by phone — would have prevented the worst outcome in most of the incidents I have cleaned up.

Updated · 2026-09-07 15:49
Signals

No signals yet — transmit the first.

Transmit a signal
© 2026 Office Proofed. All rights reserved. rendered at 60 fps