Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
AI-summarised brief · reviewed before publication
Threat hunters have detailed a widespread data‑theft and extortion campaign targeting Microsoft 365 and other SaaS platforms through fake IT help‑desk phone calls, adversary‑in‑the‑middle (AitM) token theft, and residential‑proxy sign‑ins. The operation, tracked by Arctic Wolf as PREY‑0058, mirrors tactics used by the UNC6671 group identified by Mandiant and may be linked to the Cinder/Pink threat actors. Attackers impersonate internal IT staff, lure executives to authentication‑styled URLs, and harvest credentials and MFA approvals to capture session tokens. Those tokens are replayed from proxy infrastructure to access SharePoint, OneDrive, Exchange and Box, where bulk data is exfiltrated before extortion demands are issued. No endpoint malware or lateral network movement is observed; victims span U.S. sectors such as construction, healthcare, finance and professional services. Researchers recommend Conditional Access, phishing‑resistant MFA, tighter SharePoint permissions and staff training to mitigate the threat.
💡 Why It Matters
- · By hijacking legitimate MFA flows, the attackers bypass traditional credential‑based defenses, turning trusted executive accounts into direct conduits for large‑scale data theft and ransom.