The 6-minute takeover: how one password hands over your whole Microsoft 365
A staff member gets a convincing email, clicks the link, and types their Microsoft 365 password into a login page that looks exactly right. That’s it. That’s the whole “hack.”
From that single password — belonging to an ordinary staff account, not an administrator — an attacker can go to complete control of your entire Microsoft 365 in under six minutes: every inbox, every file, every Teams chat. And before they leave, they quietly cut a spare key so they can walk back in for the next two years, even after that password is changed.
No genius required. No exotic tools. Just a chain of small, switched-off basics.
How it actually unfolds
1. One password, no second lock. The phished password is all it takes, because there’s no second step to prove it’s really them. A stolen password is a key that still works.
2. A nobody account that owned a powerful app. Here’s the twist — and the part most businesses miss. The account they landed on wasn’t an admin. It was a regular staff login. But it happened to be the registered owner of one of the apps connected to Microsoft 365 — and that app had been granted sweeping, behind-the-scenes permissions, enough to hand out admin rights. By controlling the account that owned the app, the attacker simply borrowed the app’s power. They never needed a privileged account. They just needed to own an over-privileged app.
3. Total control. Using the app’s permissions, the attacker promotes themselves to full administrator — and can now read any mailbox, reset anyone’s password, download your data, and send email as anyone in the business.
4. A spare key. Before they go, they add a hidden credential of their own — often to that same over-powered app. Change the original password all you like; they’re still in, for up to two years.
The most alarming part isn’t the speed. It’s that at least half a dozen simple controls could have stopped this at different points along the way — and not one of them was switched on.
Why this matters if you’re a small business
It’s tempting to think “we’re too small for anyone to bother.” But this isn’t a master criminal choosing you — it’s automated, opportunistic, and aimed at whoever left the door open. And Microsoft 365 is the door to everything: your email, your documents, your client data, your money.
And notice what this story breaks: even if your admin accounts are locked down tight, an everyday account owning the wrong app can hand over the lot. The good news is that, because the attack relies on skipped basics, the fixes are basics too.
The switches that stop it
- Multi-factor sign-in, everywhere. A second step on every login means a stolen password on its own is useless. This single control blocks the overwhelming majority of account takeovers.
- Mind your powerful apps — not just your admins. This is the one that mattered here. The apps connected to Microsoft 365 carry permissions of their own, and ordinary staff are often listed as their owners. Review which connected apps have sweeping access, who controls them, and switch off anything you don’t recognise or need.
- Right-sized access. No one — and no app — should hold more power than the job needs. An everyday account should never be able to grant admin rights, directly or through an app it owns.
- Protected admin accounts. Keep administrator accounts separate, locked down, and never used for day-to-day email and browsing.
- Someone watching. A new administrator, a new app credential, a sign-in from the other side of the world at 3am — these leave traces. Someone (or something) needs to be looking, so a quiet break-in doesn’t go unnoticed for months.
That last point is the difference between having security and knowing it’s working. Most of these controls map neatly to a recognised security standard — a practical way to get them in place in order, and prove they’re on.
The takeaway
The scary version of this story is “total control in six minutes, from an account that wasn’t even an admin.” The useful version is: every step in that chain had an off-switch. Flip them, keep them flipped, and watch for the warning signs, and you’re no longer the open door.
If you’d rather not work through it alone, that’s exactly what our managed cyber security does — we get these controls on, keep them on, and make it visible so you can see you’re protected. Want a free outside-in look first? Run a Security Pulse on your business in 60 seconds.
Want this handled for your business?
Book a free, no-obligation IT & security assessment. In about 30 minutes you'll know exactly where you stand — and the simplest way to fix it.