The Microsoft Login Worked. The Attacker Still Got the Session
| 20 min read
For Experts A China-aligned phishing campaign relayed real Microsoft sign-ins while stealing the resulting sessions. The defence starts with origin-bound authentication, independent verification, and a response plan that revokes more than a password.