---
title: Office 365 Man-in-the-Middle Attack Demo
description: Our incident response team is seeing an uptick in adversaries using a very tricky man-in-the-middle attack to bypass MFA and breach Office 365 tenants.
image: //info.varonis.com/hubfs/social-suggested-images/varonis-logo.png
---

[![Varonis Logo](https://info.varonis.com/hs-fs/hubfs/social-suggested-images/varonis-logo.png?width=230&height=75&name=varonis-logo.png "Varonis Logo")](https://www.varonis.com?hsLang=en)

## Office 365 Man-in-the-Middle Attack Demo

**Demo** | On-Demand | Video Replay

Our incident response team is seeing an uptick in adversaries using a very tricky man-in-the-middle attack to bypass MFA and breach Office 365 tenants.

**Here’s an outline of how the attack works:**

- We trick a user into entering creds into our fake O365 login page (made with evilginx)
- We make Microsoft send a passcode to the user’s phone
- User enters their passcode on OUR fake page
- We hijack the user’s session token
- Gain access to SharePoint Online environment
- Exfiltrate data from O365
- Pivot to on-prem and steal CEO’s emails (because why not?)

##### Share

### Watch the Replay!

![RyanOBoyle_circle](https://info.varonis.com/hs-fs/hubfs/images/headshots/RyanOBoyle_circle.jpg?width=102&height=102&name=RyanOBoyle_circle.jpg)

### Ryan O'Boyle

#### Engineer, Varonis

Our Clients

![Varonis Customers](https://info.varonis.com/hs-fs/hubfs/Varonis%20Landing/logo-white-left.png?t=1498677966558&width=600&height=66&name=logo-white-left.png)

![Varonis Customers](https://info.varonis.com/hs-fs/hubfs/Varonis%20Landing/logo-white-right.png?t=1498677966558&width=600&height=35&name=logo-white-right.png)

> “Our biggest surprise to us as a company was to finally know how much sensitive data was actually out there living on our servers.”

Gomez, Senior IT Architect, The University of Southern California

© 2026 Varonis Systems, Inc