Defending against adversary-in-the-middle threats with phishing-resistant multi-factor authentication (ITSM.30.031)

This publication provides details on observed AitM phishing campaigns to highlight their prevalence and demonstrate the risk of leaving cloud accounts vulnerable. All findings in this publication are based on over 100 campaigns that the Canadian Centre for Cyber Security (Cyber Centre) detected targeting Microsoft Entra ID accounts between 2023 and early 2025. Although this is not a comprehensive overview of all AitM phishing campaigns happening globally, it offers a snapshot of how widespread these campaigns have become.

Data and Resources

Additional Info

Field Value
Data Level
Agreement Required
Purpose Constraints
Redistribution Allowed
AI Training Allowed
Data Steward