On this page
If your business is in construction, renovation, or trades — you need to know about a phishing campaign that’s specifically targeting your industry across Canada.
Attackers are sending emails that look like they’re from project managers, suppliers, or general contractors. The emails contain links to what appear to be Microsoft login pages. The pages look identical to the real thing — same branding, same layout, even HTTPS in the address bar. But they’re fake, and they’re designed to steal your Microsoft 365 credentials.
This isn’t a generic spam blast. It’s targeted, it’s convincing, and it’s catching people who know better.
How the Scam Works
The attack follows a specific sequence:
- You receive an email that looks legitimate — an RFP, a change order, a shared document from a known contact
- You click a link that takes you to a page that looks exactly like Microsoft’s login page
- You enter your credentials because the page looks real — it even uses HTTPS
- The attacker captures your login in real time and uses it to access your Microsoft 365 account
- They hijack your authentication token — which means even if you have MFA enabled, they can bypass it by reusing the captured session
Once inside, attackers move through your email, read sensitive conversations, and impersonate you to send fraudulent messages to your contacts — clients, subcontractors, suppliers, banks.
Why Construction Is a Target
Construction companies handle high-value transactions every day. Progress payments, change orders, material invoices — these are routine communications that involve large sums of money. An attacker who gains access to a project manager’s email can intercept a payment instruction and redirect funds to a fraudulent account.
The industry also tends to have a high volume of external communication — subcontractors, vendors, consultants — which means staff are accustomed to receiving emails from unfamiliar addresses. That makes phishing harder to spot.
In Northern Ontario, where construction projects often involve multiple parties spread across communities from Thunder Bay to Timmins, the volume of email-based coordination is even higher.
Why MFA Isn’t Enough
Multi-factor authentication is essential, and every business should have it enabled. But this particular attack technique — sometimes called adversary-in-the-middle or token hijacking — can bypass standard MFA.
Here’s why: when you authenticate through the fake login page, the attacker’s system captures not just your password but your active session token. That token is what Microsoft uses to keep you logged in. The attacker replays that token and gains access without ever needing to complete MFA again.
This is a related technique to the device code phishing we described previously — both result in stolen session tokens, but the delivery mechanism differs. Device code phishing tricks users into entering a code on a legitimate Microsoft page, while this attack uses a fake login page to intercept credentials and tokens in real time.
Red Flags to Watch For
Train your team to watch for these signals:
- Unexpected RFPs or document shares from contacts you weren’t expecting to hear from
- Urgency — “review this immediately” or “your account will be locked”
- Generic language — “Dear Sir/Madam” instead of your name
- URLs that don’t match — hover over links before clicking. The domain should be exactly
login.microsoftonline.com, notlogin.microsoftonline.com.something-else.com - Requests for credentials through email — be suspicious of any email link that asks you to sign in to “verify” your account
What to Do Right Now
If you haven’t been targeted yet:
- Enable MFA on every Microsoft 365 account if you haven’t already
- Deploy identity threat monitoring — tools like Huntress ITDR watch your Microsoft 365 tenant for suspicious sign-ins, impossible travel, and token abuse in real time
- Brand your Microsoft 365 sign-in page with your company logo and colours — this makes fake login pages easier to spot
- Train your staff — not just once, but regularly. Phishing simulations help people build the reflex to pause before clicking
- Use unique passwords for every account — a password manager makes this practical
If you think you’ve been compromised:
- Stop using the affected device immediately
- Contact your IT team or provider
- Reset the compromised account’s password and revoke all active sessions
- Review sent email for any messages the attacker may have sent on your behalf
- Notify any contacts who may have received fraudulent messages
- Contact your bank if financial information was exposed
How DVG Systems Protects Against This
For our managed IT clients, the defence against this type of attack is layered:
- Identity threat detection and response (ITDR) watches Microsoft 365 tenants 24/7 for suspicious sign-ins and token abuse
- Conditional Access Policies restrict where and how users can authenticate
- Email filtering catches phishing attempts before they reach inboxes
- Security awareness training with regular phishing simulations
- Password managers make unique passwords practical, so one stolen credential does not open other accounts
Construction is one of the industries we work with across Northern Ontario. If your team is handling high-value transactions over email and you’re not confident in your security posture — that’s worth a conversation.
Book a free security assessment →
Or reach us at (807) 700-0061 or solutions@dvgsystems.com.
DVG Systems is a Thunder Bay-based managed IT provider serving businesses across Northwestern Ontario. We specialize in cybersecurity, Microsoft 365, and managed IT services for construction, trades, and professional services firms.