A new FBI advisory describes phishing that hijacks a Microsoft 365 session without stealing a password and without breaking multi-factor authentication the way you’d expect. For an SEC-registered adviser, that makes it a Regulation S-P and Rule 206(4)-7 problem — not just an IT ticket. Here is the mechanism, why your MFA won’t catch it, and the configuration changes worth making this week.
The rest of this article is free to read with a BrainTrust membership — joining takes about a minute, and no credit card is required.