{
  "id": 2234411,
  "title": "Business Email Compromise Attack Hijacks Session Token to Steal Vendor Payments",
  "url": "https://urgent.news/2026/08/20/business-email-compromise-attack-hijacks-session-token-to-steal",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T21:58:12.000Z",
  "source": {
    "name": "PYMNTS",
    "slug": "pymnts",
    "url": "https://www.pymnts.com/cybersecurity/2026/business-email-compromise-attack-hijacks-session-token-to-steal-vendor-payments/"
  },
  "original_language": "en",
  "account": "Cybersecurity firm TrendAI reported on an email compromise (BEC) scheme that involved the hijacking of a session token to steal vendor payments in August 2024. The attackers began by targeting a finance user with a spear-phishing email that appeared to be concerning a denied PTO request. The email contained personalized information, including the target's name, job title, and organization, and prompted the recipient to click a button labeled \"View Conflicting PTO Dates.\"\n\nOnce the victim clicked the malicious link, the attackers used an Adversary-in-the-Middle phishing page to bypass multi-factor authentication and hijacked the victim's live Microsoft 365 session token. With this control, the criminals were able to conceal the fraudulent activity for 30 days by setting up three malicious inbox rules to auto-archive and mark as read incoming vendor and internal collection emails.\n\nDuring this time, the attackers impersonated vendors and rerouted the company's payments to bank accounts under their control. Cybersecurity experts emphasized that this BEC campaign highlighted the modern enterprise perimeter's vulnerabilities, where trust and identity are the primary battlegrounds. The sophistication of these attacks necessitates a reevaluation of security measures, as highlighted in a PYMNTS report from December 2024. This report noted that 83% of U.S. companies had been targeted by highly sophisticated cyber fraud, with business email compromise schemes being the most prevalent.",
  "summary": "Cybersecurity firm TrendAI uncovered a business email compromise (BEC) scheme in which an attacker tricked a victim into clicking on a link and was then able to reroute payments that were sent by the victim’s company and intended for its vendors, it said in a Aug. 14 blog post. In this attack, the adversary targeted […] The post Business Email Compromise Attack Hijacks Session Token to Steal…",
  "key_points": [
    "Attackers hijacked session token to steal vendor payments in August 2024.",
    "Finance user targeted via spear-phishing email with personalized details.",
    "Fraudulent activity concealed for 30 days using malicious inbox rules."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}