Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
- ID
- 22128
- Status
- summarized
- Published
- 07 Sep 2026, 11:51 PM
- Fetched
- 08 Sep 2026, 1:06 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 08 Sep 2026, 1:12 AM
- Tags
- Audience
- developerssaas_founders
What happened
Arctic Wolf details a widespread M365 data theft and extortion campaign (PREY-0058) where attackers impersonate internal IT help desk in phone calls, directing executives to lookalike SSO/MFA domains (e.g., assignpasskey[.]com, mfaregister[.]com) that run adversary-in-the-middle login flows to steal credentials, MFA approvals, and session tokens. Stolen tokens are replayed via residential proxies matching the victim's geography and ASN, then used for discovery and data exfiltration across SaaS apps.
Why it matters
If your startup or team runs on Microsoft 365, your executives are the target—brief them that 'IT calling to set up a passkey' is the current lure, and review whether your tenant enforces session token lifetimes, conditional access policies, and impossible-travel detection. The attack bypasses MFA by stealing the authenticated session, so MFA alone is not sufficient.
Discussion angle
For teams on M365: what conditional access and session lifetime settings actually stop token replay, and how do you brief non-technical executives to hang up on unsolicited 'IT help desk' calls without creating a culture of ignoring real IT?