As cited
Copy frozen at (site build).
threat intel
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters discovered a campaign targeting Microsoft 365 and other SaaS platforms through vishing calls impersonating IT help desk staff, token theft via adversary-in-the-middle attacks, and residential proxy logins. The scheme primarily focuses on executive-level employees for data theft and extortion purposes.
Why it matters: Organizations with Microsoft 365 deployments face elevated risk from social engineering targeting executives; security teams should implement additional verification steps for credential requests and monitor for suspicious proxy-based access patterns.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters discovered a campaign targeting Microsoft 365 and other SaaS platforms through vishing calls impersonating IT help desk staff, token theft via adversary-in-the-middle attacks, and residential proxy logins. The scheme primarily focuses on executive-level employees for data theft and extortion purposes.
Why it matters: Organizations with Microsoft 365 deployments face elevated risk from social engineering targeting executives; security teams should implement additional verification steps for credential requests and monitor for suspicious proxy-based access patterns.
- Source published
- First seen by Cybersecurity Tracker