Your Employees Just Got a “Code of Conduct” Email. It Might Be a Trap.
For a long time, business owners felt a sense of security if they had multi-factor authentication (MFA) in place. We told our teams that if they had a code on their phone, they were safe. But in the current landscape, your business can no longer afford to rely on that assumption. A massive, global phishing campaign recently proved that even the most disciplined employees and the standard security protocols are being circumvented with terrifying precision.
The Microsoft Report: A 35,000-User Wake-Up Call
Microsoft recently pulled back the curtain on a large-scale phishing campaign that specifically targeted the internal policies of organizations worldwide. This wasn't a scattershot attempt at a few unlucky individuals. This was a surgical operation that reached more than 35,000 users across over 13,000 organizations in 26 different countries.

The campaign hit professional services firms, healthcare providers, and financial institutions with a simple but devastatingly effective hook: an email regarding a "Code of Conduct" violation or a new policy review.
Because these emails appear to come from internal departments like HR, compliance, or executive leadership, they instantly inherit a level of authority and trust that traditional scams lack. When an employee sees a notification that they may have violated a company policy, their immediate reaction isn't suspicion: it's anxiety and a desire to resolve the issue quickly. This is exactly what the attackers are counting on.
1. Why the “Code of Conduct” Lure Works
Modern attackers have traded their "hacker" hoodies for business suits. They understand the operational rhythm of a company like yours. They know that employees are trained to prioritize messages from administration and compliance departments. This campaign succeeds because it follows a proven psychological formula: Urgency + Trust + Action.
- Urgency: The email claims there is a "conduct-related item" that requires immediate attention. This creates a "fight or flight" response that often bypasses the logical, skeptical part of the brain.
- Trust: The message is sent using legitimate email services and often passes all technical checks like SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail). It looks "clean" to your email filters because, in many cases, it is sent from other compromised corporate accounts.
- Action: The user is directed to a login page that looks identical to their standard Microsoft 365 portal. They enter their credentials, provide their MFA code, and believe they have finished the task.
By the time the employee realizes something is wrong, the trap has already been sprung. The attacker didn't just get a password; they got something far more valuable.
2. The MFA Myth: Why Passwords Aren't the Target
One of the most dangerous misconceptions in cybersecurity today is that multi-factor authentication is a silver bullet. While we always recommend and implement MFA for our clients at Frankel Technology Services, it is important to understand its limitations.
In this specific "Code of Conduct" campaign, attackers used a technique known as Adversary-in-the-Middle (AiTM). In plain English, this means the attacker sits between your employee and the real Microsoft login page. When the employee enters their password and their MFA code, the attacker’s system passes that information to Microsoft in real-time, completes the login, and then steals the authentication token.

Think of it this way: The attacker is no longer trying to steal your key. They are trying to steal the badge that says you already used the key.
Once they have this session token (the digital proof that a user is logged in), they can "replay" it on their own machines. They don't need your password. They don't need your MFA code. They are already "in." This allows them to bypass traditional security layers and gain persistent access to your Outlook, OneDrive, and Teams data.
3. Beyond Prevention: The Critical Role of ITDR
If your security strategy starts and ends with "preventing the click," you are fighting a losing battle. The reality is that no system is 100% breach-proof. Even with the best training, someone in your organization will eventually click the wrong link or approve a suspicious prompt.
This is why we have shifted our focus toward Identity Threat Detection and Response (ITDR). While traditional antivirus software looks for malicious files on a computer, ITDR looks for malicious behavior within your identity accounts (like Microsoft 365).
At Frankel Technology Services, we utilize tools like Huntress to provide this layer of oversight. ITDR allows us to monitor for signs of "token theft" and session hijacking that traditional tools might miss.
- Detecting Anomalous Logins: If an authentication token was generated in Chicago but is suddenly used five minutes later from an IP address in another country, ITDR flags this as "impossible travel."
- Monitoring Session Activity: ITDR can alert us when a new, unauthorized device is registered to an account or when suspicious mailbox rules are created (a common tactic attackers use to hide their presence).
- Rapid Response: Once a threat is detected, we can ensure the immediate revocation of all active tokens, effectively "logging out" the attacker before they can exfiltrate sensitive data.
4. Building a “Slow Down and Verify” Culture
Technology is only half of the equation. To protect your business, you must also foster a culture where employees feel empowered to verify requests that seem out of the ordinary.

Attackers rely on routine behavior. We get so used to clicking "Accept" and "Allow" that we do it on autopilot. To counter the "Code of Conduct" trap, we recommend teaching your team the following:
- Verify the Source: If you get an email about a policy violation or a mandatory review, don't click the link in the email. Instead, go directly to your company’s internal HR portal or contact your manager through a separate channel (like a phone call or a fresh Teams message) to ask if the request is legitimate.
- Be Wary of Device Codes: If an email asks you to go to a Microsoft page and enter a short numeric code that you didn't personally request, STOP. This is a specific type of attack called Device Code Phishing that is designed to grant an attacker full access to your account.
- Report the "Near Misses": Encourage a culture where reporting a suspicious email is praised, not ignored. The sooner your IT partner knows about a lure, the sooner we can monitor the rest of the organization for similar attempts.
5. What Your Business Should Review Immediately
To ensure your organization is prepared for these evolving identity-based attacks, there are several technical and strategic areas you should audit today. We can help you focus on these critical items:
- Conditional Access Policies: These are rules that control how and when users can log in. We can set policies to block logins from high-risk locations or require that logins only happen from "compliant," company-managed devices.
- Token Lifetime and Revocation: Review how long your sessions stay active. Reducing the lifetime of an authentication token can significantly reduce the risk of a stolen token being useful to an attacker.
- Authentication Flow Audits: If your organization doesn't need "Legacy Authentication" or specific "Device Code" flows, they should be disabled entirely to reduce your attack surface.
- Incident Response Planning: Does your team know what to do if a session is hijacked? Having a clear process for revoking tokens and resetting identities is vital for minimizing damage.
Let’s Strengthen Your Shield Together
The "Code of Conduct" phishing campaign is a stark reminder that the digital landscape is constantly evolving. Attackers are no longer just looking for a way into your network; they are looking for a way to become your users.
At Frankel Technology Services, we specialize in helping professional services firms and growing organizations navigate these complex threats. We don't just keep your systems running; we provide the strategic guidance and proactive monitoring you need to stay secure in an era where identity is the new perimeter.
Let's talk about how we can audit your Microsoft 365 environment and implement the ITDR protections your business deserves. Together, we can ensure that your employees aren't just your greatest asset, but also your strongest line of defense.