Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-04 and was added to the RWP archive on 2026-09-07.
"Code of conduct" mail was HR shame as an AiTM kit — 35,000 users, 13,000 orgs
Microsoft Defender Research watched a multi-stage compliance lure, clean mail infrastructure, and a real Microsoft sign-in proxied for tokens — mostly US, mid-April 2026.
Bottom line up front
CONFIRMED Between 14 and 16 April 2026, Microsoft Defender Research observed a campaign against more than 35,000 users at over 13,000 organizations in 26 countries (92% United States). Lure: you violated the code of conduct. Mail came from attacker-controlled domains through legitimate sending services, so it authenticated. Multi-step pages, Cloudflare CAPTCHAs, encryption-style banners, then "Sign in with Microsoft" into an adversary-in-the-middle proxy that captured tokens after the user completed MFA.
This is not Tycoon2FA as a named kit in Microsoft's write-up. It is the same class of problem: phishable MFA plus a real login page.
Historical backfill of 4 May 2026 reporting; added 7 September 2026.
What happened
Shame plus a calendar/sign-in step. Barracuda's MSP note matches Microsoft's user/org counts and the "clean infrastructure" point: no botnet, no obviously malicious sending IP. OTX collected lure domains (acceptable-use-policy-calendly.de, cocinternal.com, and similar).
Why it mattered
Compliance and HR mail is designed to make people click. Token theft means the SOC sees a successful sign-in from the victim's geography if the proxy is good enough.
Who / what was affected
Mostly US; healthcare and financial services among Barracuda-named verticals. OT not applicable.
Technical context
FIDO2/passkeys break the proxy. Conditional access that rejects unfamiliar client apps and impossible travel still helps. User education that "HR would not make you sign in to a third-party portal to discuss a conduct case" is the human control.
Exploitation / threat status at the time
CONFIRMED Microsoft volume and chain.
REPORTED specific lure domains via secondary intel.
What defenders should have done
- Quarantine external mail that impersonates HR/compliance without an internal ticket ID.
- Require phishing-resistant MFA for all cloud mail users, not just admins.
- Hunt consent/session anomalies in the 14–16 April window.
RWP assessment
Confidence: High on Microsoft's campaign sketch. Shame is a reliable initial-access primitive.
Defensive actions
- Passkeys.
- Report-phishing button that actually reaches the SOC the same day.
- Token revocation runbook when a user says they "cleared up an HR thing online."
Sources
- Microsoft Defender Research — Breaking the code: multi-stage code of conduct phishing
- Barracuda — The code of conduct phishing campaign: what MSPs need to know
- AlienVault OTX — Pulse on the Microsoft code-of-conduct campaign