Published on September 7, 2026

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks


Severity
Medium

Detail

Threat hunters have identified a widespread data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms through fake IT support calls, AitM phishing, MFA theft, and session-token replay. The activity, tracked as PREY-0058, primarily targets executives such as directors and vice presidents. Attackers impersonate internal IT or help desk staff and direct victims to fake authentication and MFA registration websites.

The AitM login pages capture credentials and MFA approvals, allowing attackers to obtain valid Microsoft 365 session tokens. These tokens are then replayed through residential proxy infrastructure to access the victim’s cloud environment. After gaining access, attackers perform Entra ID and SharePoint reconnaissance, followed by bulk data collection from SharePoint, OneDrive, Exchange, and Box. The stolen information is subsequently exfiltrated and used for extortion.

The campaign is notable because it does not require endpoint malware or traditional lateral movement, making abnormal cloud authentication, token replay, SharePoint searches, and large-scale data access important detection opportunities.

How?

The attack begins with threat actors impersonating internal IT or help desk personnel through phone calls. Victims are instructed to visit authentication-themed URLs that appear to be related to their organization’s Microsoft 365 or MFA setup.

The links redirect victims to attacker-controlled Adversary-in-the-Middle (AitM) login pages that mimic legitimate Microsoft 365 authentication. The attackers capture the victim’s credentials and MFA approval, allowing them to obtain authenticated session tokens.The stolen tokens are then replayed from residential proxy infrastructure or IP addresses that appear to match the victim’s location and network characteristics, helping the attackers blend in with legitimate activity.

Once access is obtained, attackers perform reconnaissance against Microsoft Entra ID and SharePoint to identify the victim’s applications, permissions, sites, and accessible data. They then conduct bulk searches and collection across SharePoint, OneDrive, Exchange Online, and Box.

The collected information is subsequently exfiltrated and used to pressure victims through data extortion demands. Unlike traditional compromises, the attackers do not need to install malware or perform network-based lateral movement, making cloud authentication and abnormal SaaS activity key detection points.

Conclusion

This campaign demonstrates how threat actors can compromise Microsoft 365 environments without deploying traditional endpoint malware. By combining vishing, AitM phishing, MFA interception, session-token theft, residential proxies, and cloud data collection, attackers can maintain access while blending into legitimate user activity. Security teams should implement Conditional Access policies and phishing-resistant MFA, particularly for privileged and executive accounts. Organizations should also restrict unnecessary SharePoint and OneDrive access and regularly review cloud permissions.

Defenders should monitor for anomalous residential-proxy sign-ins, suspicious token replay, unusual SharePoint discovery activity, bulk file access, mailbox harvesting, and authentication-themed newly registered domains. Finally, employees and help desk personnel should be trained to recognize fake IT support calls and should never approve unexpected MFA requests or access authentication links provided during unsolicited phone calls.

Source

https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html