Microsoft researchers uncovered a campaign called CaptiveCrunch, tied to the Russia-linked group Storm-2945, also known as Midnight Blizzard, that sent over 200 phishing emails to roughly 120 organizations in a month. The emails do not try to steal a password. Instead, victims are led to a genuine Microsoft login and consent screen, and one click on Accept hands the attacker a token with standing access to mail, files, Teams, and calendar data, no password or MFA prompt bypassed.
For a Florida firm running Microsoft 365, this is a direct hit on the systems holding privileged client communication, and it stays invisible to password based monitoring since no password was ever compromised.
Rule 4-1.6 requires reasonable efforts that extend to the permission layer behind the login screen, not just the screen itself.
ArisGate is built to catch and close exactly this kind of gap. Schedule a free security audit today.