Microsoft Defender Experts identified a sophisticated multi-stage AiTM phishing and BEC campaign targeting financial services organizations, originating from a compromised vendor and using an indirect proxy technique to steal session cookies and MFA credentials. The attackers exploited misconfigured MFA policies to update authentication methods without challenges, then launched a second-stage phishing campaign to 16,000+ contacts. The attack was conducted by Storm-1167 and demonstrates the evolving complexity of identity compromise threats requiring comprehensive remediation beyond standard password resets.