Warning: Phone-Based Attacks Impersonate IT Staff to Steal Data from Microsoft 365

Views: 32 views

493/69 Wednesday, September 9, 2026

Cybersecurity researchers have disclosed a threat campaign targeting senior executives, such as directors and company vice presidents, to steal data and conduct extortion. The attackers focus on Microsoft 365 and other cloud-based software-as-a-service (SaaS) platforms. The threat actors use phone-based social engineering, or vishing, while impersonating IT staff or help desk personnel to trick victims into granting access to critical organizational systems. Initial activity has been observed targeting organizations in the United States, particularly in the construction, healthcare, real estate, and financial sectors.

The threat group, tracked as PREY-0058 or UNC6671, begins the attack by calling victims and directing them to fake websites with names resembling the organization’s authentication systems. These pages are used to capture login credentials and multi-factor authentication (MFA) approvals through an adversary-in-the-middle (AiTM) technique. Once access tokens are obtained, the attackers use them through proxy networks with geographic locations matching the victims to evade detection. A key aspect of this attack is that the attackers do not need to install malware on the device. Instead, they focus on searching and accessing cloud services such as SharePoint, OneDrive, Exchange, and Box to exfiltrate large volumes of data and use it as leverage for extortion.

To reduce the risk of this type of attack, administrators should consider implementing strict conditional access policies and enforcing phishing-resistant MFA. Organizations should also limit access to internal data based on the principle of least privilege. For initial detection, security teams should monitor for abnormal token reuse through proxies, unusual searches in SharePoint, and large-scale data downloads in a short period. Most importantly, organizations should provide awareness training to employees, especially executives and IT staff, so they can recognize and respond appropriately to phone-based social engineering attacks.

Source: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html