securityonline.info 9 Sept 2026, 17:16 UTC

Hackers Use Fake IT Calls to Hijack Microsoft 365 Accounts

Hackers Use Fake IT Calls to Hijack Microsoft 365 Accounts
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

HACKERS are targeting senior Microsoft 365 accounts with highly tailored vishing campaigns that mimic internal IT helpdesk calls. The PREY-0058 operation, which aligns with UNC6671/BlackFile in some threat intelligence, starts with a phone call to executives claiming an urgent security update requires a new passkey.

Victims are then guided to a malicious AiTM phishing portal that imitates legitimate internal domains, enabling attackers to harvest session tokens and gain unauthorised access to Microsoft 365 and linked SaaS platforms without exploiting a software vulnerability.

Once inside, the group focuses on data exfiltration rather than malware deployment. They route stolen sessions through residential networks using NodeMaven Proxy to obscure their location and evade travel-based alerts. Operators harvest emails via the One Outlook Web Access client and perform broad wildcard searches across SharePoint and OneDrive to download large volumes of documents.

After the theft, they contact the victim executives to demand a ransom paid through TOX messaging, imposing a strict 72-hour deadline. There is no indication of file encryption being used in these breaches; the emphasis is on exfiltration of sensitive cloud data.

Defence guidance points to strengthening phishing-resistant authentication (for example, FIDO2 hardware keys) and implementing strict helpdesk verification procedures. Organisations are advised to require employees to hang up and dial a known internal number to verify any IT request. The campaign is actively tracked by threat intelligence firms and underscores the need for robust identity controls and verification processes to mitigate vishing-led data extortion in Microsoft 365 environments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline