Historical intelligence backfill. This assessment covers reporting originally published on 2026-05-04 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

"Code of conduct" mail was HR shame as an AiTM kit — 35,000 users, 13,000 orgs

Microsoft Defender Research watched a multi-stage compliance lure, clean mail infrastructure, and a real Microsoft sign-in proxied for tokens — mostly US, mid-April 2026.

RWP Ventures · 2026-09-07 · event 2026-04-14 · 2 min read · priority 8.1

Bottom line up front

CONFIRMED Between 14 and 16 April 2026, Microsoft Defender Research observed a campaign against more than 35,000 users at over 13,000 organizations in 26 countries (92% United States). Lure: you violated the code of conduct. Mail came from attacker-controlled domains through legitimate sending services, so it authenticated. Multi-step pages, Cloudflare CAPTCHAs, encryption-style banners, then "Sign in with Microsoft" into an adversary-in-the-middle proxy that captured tokens after the user completed MFA.

This is not Tycoon2FA as a named kit in Microsoft's write-up. It is the same class of problem: phishable MFA plus a real login page.

Historical backfill of 4 May 2026 reporting; added 7 September 2026.

What happened

Shame plus a calendar/sign-in step. Barracuda's MSP note matches Microsoft's user/org counts and the "clean infrastructure" point: no botnet, no obviously malicious sending IP. OTX collected lure domains (acceptable-use-policy-calendly.de, cocinternal.com, and similar).

Why it mattered

Compliance and HR mail is designed to make people click. Token theft means the SOC sees a successful sign-in from the victim's geography if the proxy is good enough.

Who / what was affected

Mostly US; healthcare and financial services among Barracuda-named verticals. OT not applicable.

Technical context

FIDO2/passkeys break the proxy. Conditional access that rejects unfamiliar client apps and impossible travel still helps. User education that "HR would not make you sign in to a third-party portal to discuss a conduct case" is the human control.

Exploitation / threat status at the time

CONFIRMED Microsoft volume and chain.

REPORTED specific lure domains via secondary intel.

What defenders should have done

  1. Quarantine external mail that impersonates HR/compliance without an internal ticket ID.
  2. Require phishing-resistant MFA for all cloud mail users, not just admins.
  3. Hunt consent/session anomalies in the 14–16 April window.

RWP assessment

Confidence: High on Microsoft's campaign sketch. Shame is a reliable initial-access primitive.

Defensive actions

  1. Passkeys.
  2. Report-phishing button that actually reaches the SOC the same day.
  3. Token revocation runbook when a user says they "cleared up an HR thing online."

Sources

  1. Microsoft Defender Research — Breaking the code: multi-stage code of conduct phishing
  2. Barracuda — The code of conduct phishing campaign: what MSPs need to know
  3. AlienVault OTX — Pulse on the Microsoft code-of-conduct campaign