7 Unexpected Ways Criminals Get Into Business Accounts
Most account takeovers still start with a phishing email or a weak, reused password. But as more businesses switch on multi-factor authentication (MFA), criminals have moved to routes that go around it. Here are seven of them, and what closes each one.
If you want the basics first, our guide to fake Microsoft 365 sign-in pages covers the most common attack in detail.
1. Stealing your signed-in session
When you sign in to Microsoft 365 or a website, your browser keeps a token, often stored in a cookie, so you don’t have to sign in on every click. If a criminal copies that token, they can use your session without your password or your MFA code. Microsoft calls this token theft.
Tokens are usually stolen by “information-stealing” malware on a device, or by a phishing page that relays your sign-in to the real site.
The fix: keep devices patched and protected, allow Microsoft 365 sign-ins only from devices your business manages, and if you suspect anything, sign the user out of every session as well as changing the password.
2. Taking over your mobile number
In a SIM swap, a criminal persuades your mobile network to move your number onto a SIM they hold. From then on, your calls and texts, including MFA codes and bank one-time passcodes, go to them. Cifas, the UK fraud prevention service, recorded a 402% rise in unauthorised SIM swap cases in the first six months of 2026 compared with the same period in 2025.
The fix: don’t rely on text messages for MFA on important accounts. Use an authenticator app or a passkey, ask your network about extra account security such as a PIN or password, and treat a sudden loss of signal as an emergency.
3. Getting you to approve a rogue app
“Consent phishing” skips your password altogether. You’re sent a link to a real Microsoft sign-in page, where an app asks for permission to “read your mail” or “access your files”. Click Accept and the app, which belongs to the attacker, gets ongoing access to your data. Because the screen is genuine, it doesn’t feel like phishing.
The fix: in Microsoft 365, stop staff from approving apps themselves and send requests to an administrator instead. Review which apps already have access and remove any nobody recognises.
4. Wearing you down with MFA prompts
If an attacker already has a password, they can trigger sign-in prompts on your phone again and again, often late at night, until someone taps Approve to make them stop.
The fix: use number matching, where you have to type a number shown on the sign-in screen, and teach staff that an unexpected prompt means someone has their password. They should deny it and report it, then change the password. Phishing-resistant passkeys, which the NCSC now recommends wherever a service supports them, remove the problem entirely.
5. Faking a colleague’s voice or face
AI tools can now imitate a real person’s voice and face from recordings that are easy to find, such as webinars, videos and voicemail greetings. In 2024 the engineering company Arup confirmed it had lost about £20m after an employee in Hong Kong joined a video call with deepfakes of senior colleagues and made the payments they asked for.
The fix: agree a rule that payments and changes to bank details are always confirmed through a second, known channel, such as calling back on a number you already hold. No exceptions for urgency or seniority.
6. Reusing passwords from old breaches
Passwords leaked from one website get tried, automatically, on thousands of others. This is called credential stuffing. If a member of staff used their work email and a familiar password to sign up for something years ago, that pair may already be on a list.
The fix: a unique password for every account, kept in a password manager. The NCSC suggests checking Have I Been Pwned to see whether your details have appeared in a public breach. Our guide to creating strong passwords has more.
7. Talking the help desk into a reset
Why phish a password when you can ask for a new one? Attackers phone or message help desks pretending to be a member of staff who has lost their phone, and ask for a password reset or for MFA to be removed. In July 2025, the chairman of M&S told MPs that its attackers had got in through “sophisticated impersonation” that involved a third party.
The fix: whoever handles IT requests, inside your business or outside it, should verify identity before any reset, for example by calling back on a number already on file or getting approval from a manager. It’s worth asking your IT provider what their process is.
From our work
We haven’t had a fake reset request yet, but the checks are already in place. Before we reset anyone’s password, we call their line manager on their mobile to confirm the request is genuine, because with AI voice cloning, a familiar voice on the phone is no longer proof. We also send a push notification that the person has to approve before the reset goes ahead.
David Gilbey, Just Gilbey IT Solutions
The common thread
Every one of these relies on a gap between “signed in” and “should be trusted”. Closing it comes down to a short list:
- MFA on every account, moving to passkeys where you can.
- Sign-ins allowed only from managed, up-to-date devices.
- Accounts watched for odd sign-ins, new inbox rules and new app permissions.
- Clear rules for payments, bank details and password resets.
- Staff who know these tricks exist.
Under the April 2026 Cyber Essentials requirements, MFA is mandatory for cloud services that offer it, so the first item isn’t optional if you hold the certificate.
Our cyber security service helps with most of that list: Microsoft 365 hardening with MFA, 24/7 monitoring of devices and accounts, and security awareness training for your team.
Questions people ask
Can someone get into my account without my password?
Yes. If they steal the session your browser keeps after you sign in, or trick you into giving an app permission to your mailbox, they don’t need your password at all. Signing out of all sessions and removing unknown apps cuts that access off.
How do I know if my SIM has been swapped?
The usual sign is that your phone suddenly loses signal and shows “SOS only” or “no service” somewhere it normally works, while you start getting emails about password resets. Contact your mobile network from another phone straight away.
Is a text message code good enough for multi-factor authentication?
It’s much better than nothing, and the Cyber Essentials requirements say so. But SMS codes can be intercepted through a SIM swap, so use an authenticator app or, better, a passkey where the service offers one.
Sources
- Cifas: Fraudscape 2026, 6 month update
- Microsoft Security blog: Token tactics, how to prevent, detect and respond to cloud token theft
- Microsoft Learn: Protect against consent phishing
- NCSC: Passkeys are more secure than traditional ways to log in (April 2026)
- Computing: Deepfake fraud costs engineering giant Arup £20m
- BleepingComputer: M&S confirms social engineering led to ransomware attack
- NCSC: Data breaches, guidance for individuals and families
- NCSC: Cyber Essentials requirements for IT infrastructure v3.3 (April 2026)