For years, turning on multi-factor authentication (MFA) was the single best thing a small business could do to protect its Microsoft 365 accounts, and it still matters. But through 2026, a wave of adversary-in-the-middle (AiTM) phishing attacks has shown that MFA on its own is no longer enough. Canada's own threat researchers have documented more than 100 AiTM phishing campaigns aimed specifically at Canadian Microsoft 365 tenants, and small and mid-sized businesses are a prime target. For companies in North York and across the Greater Toronto Area, that means the login screen your team uses every morning has become one of the main ways attackers try to get in.
What adversary-in-the-middle phishing actually is. In a traditional phishing attack, a criminal tricks you into typing your password into a fake page and then reuses that password later. AiTM goes a step further. The attacker sits invisibly between you and the real Microsoft login, relaying everything in real time through a reverse-proxy toolkit. You receive a convincing email, often about a shared document, a voicemail or an expired password, and click through to a page that looks exactly like the genuine Microsoft 365 sign-in. When you enter your username and password and even approve the MFA prompt on your phone, the attacker captures all of it and passes it straight to Microsoft on your behalf.
Why your password was never the real target. The important thing to understand is that the attacker is not really after your password. They are after the session token, the small piece of data Microsoft hands your browser after a successful login so you don't have to re-authenticate on every click. Because you completed the MFA step for them, that token is fully valid. By stealing it, the criminal effectively clones your logged-in session and walks straight into your mailbox, Teams and SharePoint without ever being asked for a code again. They let you do the work of logging in, then walk off with the key.
What happens once they are inside. Once an attacker is in a business mailbox, the goal is rarely to make noise. They quietly read email to learn how your company handles invoices and payments, set up hidden inbox rules to cover their tracks, and then send believable messages from a trusted internal address, a technique known as business email compromise. A fake wire-transfer request that comes from your own controller's real account is far harder to catch than a clumsy outside scam. This is how many six-figure fraud losses at small Ontario businesses begin.
Why the attacks are so convincing now. What makes today's attacks especially dangerous is polish. Generative AI has removed the old warning signs, the broken grammar and awkward phrasing that used to give phishing away. The messages are clean, correctly branded, and often reference real projects or colleagues pulled from earlier breaches. A common version is a text message or email claiming your multi-factor authentication has expired and must be re-verified, designed to rush a busy employee into handing over a one-time code. When the message looks right and the request feels urgent, even careful, well-trained staff can be fooled.
The defence that actually works: phishing-resistant MFA. AiTM attacks are stoppable, but it takes layers, not a single switch. The strongest defence is phishing-resistant MFA, such as FIDO2 security keys or passkeys and Microsoft Authenticator's number-matching, which are bound to the real login and cannot be relayed through a fake proxy page. Alongside that, Conditional Access policies let you restrict sign-ins to trusted devices and locations, and token protection can tie a session to the specific device it was issued on, so a stolen token is useless anywhere else. Set up correctly, these controls close the exact gap AiTM relies on.
Lock down email, then watch for trouble. Login controls are only half the picture. Strong email authentication using DKIM, SPF and DMARC makes it much harder for criminals to spoof your domain and impersonate your staff in the first place, and it pairs naturally with an intelligent mail-filtering layer that catches AiTM lures before they ever reach an inbox. This is where a service like our own SpamFalcon does the quiet work of screening malicious links and attachments around the clock. Add continuous monitoring that flags a login from an unusual country, a newly created inbox rule or an impossible-travel event, and you move from hoping nothing gets through to catching it within minutes.
Why a local partner matters. For most small businesses, the hard part isn't knowing that these controls exist, it's configuring them correctly across Microsoft 365, keeping them current, and having someone watching when an alert fires at 2 a.m. That is the role of a local managed IT partner. As a North York-based team, Primary Support Systems can sit down with you in person, review your Microsoft 365 tenant, and switch on the right protections in an afternoon rather than leaving them buried in a settings menu. Being local also means that when something looks wrong, you are talking to an engineer who knows your environment, not a ticket queue three time zones away.
What to do this week. If you do nothing else, start here: confirm every user account has MFA enabled and move your most sensitive accounts to phishing-resistant methods; review your Microsoft 365 sign-in logs for logins from unfamiliar locations; check each mailbox for inbox rules you didn't create; and make sure your team knows that Microsoft will never text them to re-verify an expired code. These four steps alone close the doors attackers use most often.
Not sure where your business stands? Primary Support Systems offers North York and Greater Toronto Area businesses a no-charge Microsoft 365 security review. A senior engineer will check your tenant for the exact weaknesses AiTM phishing exploits and give you a clear, plain-language plan to fix them. Reach out through our contact page to book yours, and turn your login screen back into the strong front door it should be.
Want a real number?
Get a free, tailored quote from our team.
A senior Primary Support Systems engineer will scope your situation and send you a tailored, fixed-fee quote at no charge.
Request a free quote
