---
title: Office 365 Man-in-the-Middle Attack Demo
description: Office 365 Man-in-the-Middle Attack Demo
image: //info.varonis.com/hubfs/Toyota.png
---

[![Varonis Logo](https://info.varonis.com/hs-fs/hubfs/social-suggested-images/varonis-logo.png?width=230&height=75&name=varonis-logo.png "Varonis Logo")](https://www.varonis.com?hsLang=en-gb)

Video Replay

# Office 365 Man-in-the-Middle Attack Demo

![](https://fast.wistia.com/embed/medias/carphx5mzk/swatch)

About “Office 365 Man-in-the-Middle Attack Demo”

Presented By ![Steven Nesbitt](https://info.varonis.com/hubfs/Steven%20Nesbitt.jpg) Steven Nesbitt

Our incident response team is seeing an uptick in adversaries using a very tricky man-in-the-middle attack to bypass MFA and breach Office 365 tenants.

**Here’s an outline of how the attack works:  
**

- We trick a user into entering creds into our fake O365 login page (made with evilginx)
- We make Microsoft send a passcode to the user’s phone
- User enters their passcode on OUR fake page
- We hijack the user’s session token
- Gain access to SharePoint Online environment
- Exfiltrate data from O365
- Pivot to on-prem and steal CEO’s emails (because why not?)

| Request Your Own Demo! |
| --- |

“Certain alerts will trigger scripts that will disable accounts to prevent further harmful actions. This has helped minimize or eliminate the impact from ransomware attacks.”

Aaron Neilson, System Administrator, Natures Sunshine Products

![sandisk logo.png](https://info.varonis.com/hs-fs/hubfs/sandisk%20logo.png?width=120&name=sandisk%20logo.png "sandisk logo.png")

![JuniperNetworks.png](https://info.varonis.com/hs-fs/hubfs/JuniperNetworks.png?width=119&name=JuniperNetworks.png "JuniperNetworks.png")

![ChildrensHospital-1.png](https://info.varonis.com/hs-fs/hubfs/ChildrensHospital-1.png?width=141&name=ChildrensHospital-1.png "ChildrensHospital-1.png")

© 2026 Varonis Systems, Inc