AI Weekly Malaysia

Back to items Summaries

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

ID
22128
Status
summarized
Published
07 Sep 2026, 11:51 PM
Fetched
08 Sep 2026, 1:06 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
08 Sep 2026, 1:12 AM
Tags
Audience
developerssaas_founders

What happened

Arctic Wolf details a widespread M365 data theft and extortion campaign (PREY-0058) where attackers impersonate internal IT help desk in phone calls, directing executives to lookalike SSO/MFA domains (e.g., assignpasskey[.]com, mfaregister[.]com) that run adversary-in-the-middle login flows to steal credentials, MFA approvals, and session tokens. Stolen tokens are replayed via residential proxies matching the victim's geography and ASN, then used for discovery and data exfiltration across SaaS apps.

Why it matters

If your startup or team runs on Microsoft 365, your executives are the target—brief them that 'IT calling to set up a passkey' is the current lure, and review whether your tenant enforces session token lifetimes, conditional access policies, and impossible-travel detection. The attack bypasses MFA by stealing the authenticated session, so MFA alone is not sufficient.

Discussion angle

For teams on M365: what conditional access and session lifetime settings actually stop token replay, and how do you brief non-technical executives to hang up on unsolicited 'IT help desk' calls without creating a culture of ignoring real IT?

Top