For the price of a used laptop, a nobody can flood your team with flawless, custom fakes that beat the second login you thought was protecting you. Here is exactly how it works, three things you can do today, and an hour with me to shut the rest of the doors.
Save My Seat →Thursday, July 9, 2 PM ET. No charge, no pitch.
The problem: A criminal no longer needs any skill to run a slick phishing scam. For about six hundred dollars a month they rent an AI kit that writes a fresh, personalized fake for every target, goes straight for your Microsoft 365 logins, and is built to slip past the texted code most offices count on.
The solution: You can't stop the kit from existing. You can take away what it is hunting for. By the end of this article you will have three things you can do today, and you will understand why your second login isn't the seatbelt you thought it was.
In this article
Here is the way it actually goes. Your accounts-payable person, a careful one who has never fallen for anything, opens an email that looks like it came from a vendor you really use. It references a real invoice number. It is signed by a name they recognize. It says a payment detail changed and asks them to sign in to confirm it.
The link opens a Microsoft sign-in page that looks identical to the real one, down to the last pixel. They type their email, their password, and the six-digit code off their phone. The page says thank you. Nothing looks wrong. They go back to their afternoon.
Nothing is wrong, as far as anyone can see, for about a week. That is how long the hoser quietly reads that mailbox, learns who pays whom, and waits for a real invoice to come through so they can change the bank details on it. The first anyone hears of it is when a customer asks why they paid a stranger. So how did a no-name crook pull off something that clean? They didn't. They rented it.
Sold quietly in the corners of the internet, the kit does all the hard work a skilled crook used to do by hand. It rents for between six hundred and fifteen hundred dollars a month, about what a small shop pays for one decent software subscription.
The renter hands it a list of targets and it takes over from there. The AI reads what is public about each person, the company website, a LinkedIn page, an old press mention, and writes each one a different email that sounds like it came from their own bank, their own coworker, or a vendor they actually pay. It builds the fake login page. It sends the wave. In one batch researchers looked at, no two messages were alike, which is exactly the point: your spam filter blocks what it has seen before, and it has never seen any of these. Attacks like this have jumped about 1,380 percent.
So the thing that used to protect you, that a good scam took real effort, is gone. The effort is now a monthly fee.
This is the part most business owners have never had explained, and it is the part that matters most. Almost everyone believes the six-digit code texted to a phone is the seatbelt. Against this kit, it isn't, and here is why, in plain English.
Think of the fake page as a puppet standing between your employee and the real Microsoft. When your employee types their password into the puppet, the puppet types that same password into the real Microsoft at the very same instant. When Microsoft texts the code, your employee reads it off their phone and types it into the puppet, and the puppet types it into Microsoft. The code worked perfectly. It just let the wrong person in.
And it gets worse by one important step. Once you are signed in, Microsoft hands your browser a kind of day pass, a little file that says "this one is already logged in," so it does not have to ask for your password all day. The puppet grabs that pass. From then on the hoser does not need your password or your code ever again. They just show the pass. That is why "we turned the second login on" and "we are safe" are two different sentences.
None of this means the second login is worthless. It still stops the lazy attacks, and you should keep it on. It just is not the wall people think it is, and knowing that changes what you do next.
You do not have to wait for me to start closing this gap. Here are three steps that cost nothing and matter more than any gadget.
The typos are gone, so stop grading the writing. Grade the ask. Anything that pushes you to hurry, to keep it quiet, to make a payment, or to hand over a password is the red flag, no matter how clean it looks. Tell your team the rule out loud: a real vendor will never mind if you call a number you already have on file to confirm a change before you act.
Ask whoever runs your email to switch your second login from a texted code to a "phishing-resistant" one, a passkey, or the kind of app prompt where you tap a matching number on the screen. There is no code to read out and type into a fake page, so the puppet has nothing to steal. Same idea you already use, with the one weak spot taken out.
A stolen login is one way in. An unpatched program is another, and that one you can shut without anyone clicking a thing. The apps nobody thinks about, the PDF reader, the accounting add-on, the old tool still sitting on a back-office machine, are open doors a hoser walks straight through. Make a habit of updating them, not just Windows itself.
Do those three and you have taken away most of what the kit is hunting for. The piece left over is the one you usually can't see on your own: which doors are already open on your machines right now. That is what I do live.
These messages are built in a lab to beat a busy human on a Tuesday afternoon. Expecting every employee to spot every one of them, every time, is not a plan. The plan is fewer open doors and a couple of simple habits.
I have spent more than thirty-five years watching how these attacks work. FBI InfraGard, zero ransomware on any client I have worked with. And the hosers still got to my own father, with a cybersecurity expert for a son. He let them onto his computer, and I stopped them remotely just before they reached the spreadsheet with all his bank passwords. We were lucky. That night is the whole reason I made seeing your open doors simple.
The three steps above are yours to do today. Finding the doors you can't see is the part I will walk you through, live, in plain English. No guesswork about how it works, here are the three steps.
✅ No charge, and nothing to buy on the call.
✅ It is not a pitch-fest. You will leave with real steps whether or not you ever buy a thing.
✅ Plain English. No jargon, and no talking down to you.
✅ Come live if you can, that is where I answer your questions. Saved a seat but can't make it? I'll send you the replay.
✅ If your setup is in good shape, I will tell you so. No scare tactics.
✅ Straight talk. I will show you what is "open" and "at risk," never "guaranteed."
You just read why not. The kit writes a brand-new fake for every target, so the filter has nothing to match, and the puppet trick walks right past a texted code. Those tools help, and they are not the wall people think. The gap it aims for is a busy person and an open door.
An hour now shows you where that gap is on your own machines. If you are already locked down tight, you will walk away knowing it.
The rented kits only get cheaper and smarter from here, and you don't have to keep up with all of it. Spend one hour with me, walk away knowing exactly what to close first, and trade that low hum of worry for the quiet confidence of an owner who knows his doors are shut.
Save My Seat →Thursday, July 9, 2 PM ET. No charge, no pitch.
Want this kind of plain-English security news every week? Sign up for Craig's Insider Notes at CraigPeterson.com.
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals