<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks]]></title><description><![CDATA[<p dir="auto">Threat hunters have detailed a broad data theft and extortion campaign that is actively targeting Microsoft 365 and other software-as-a-service (SaaS) environments. The attack chain is notable for its reliance on help desk vishing, adversary-in-the-middle (AitM) token theft, and the use of residential-proxy infrastructure to mask malicious sign-ins.</p>
<p dir="auto">The campaign specifically singles out high-level corporate officers, including directors, vice presidents, and other executive staff. By impersonating legitimate IT support personnel, the attackers initiate phone calls to these high-value targets in an attempt to lower their guard and extract credentials or approve multi-factor authentication (MFA) prompts.</p>
<p dir="auto">Once initial access is established via stolen session tokens, the threat actors leverage residential proxies to make their traffic appear as if it originates from trusted, local IP addresses. This technique is designed to bypass geographic and risk-based conditional access policies that security teams often rely on.</p>
<p dir="auto">The ultimate goal of the operation is data exfiltration followed by extortion. The disclosure serves as a reminder that even with robust technical controls in place, social engineering remains a primary vector for compromising enterprise SaaS accounts.</p>
<ul>
<li><strong>Primary Targets:</strong> Executive staff (Directors, VPs, C-suite).</li>
<li><strong>Initial Vector:</strong> IT help desk vishing (voice phishing).</li>
<li><strong>Key Technique:</strong> AitM token theft to bypass MFA.</li>
<li><strong>Evasion Method:</strong> Residential-proxy sign-ins to circumvent IP-based security policies.</li>
<li><strong>Impact:</strong> Data theft and subsequent extortion.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given the focus on C-suite and executive roles, is your organization adjusting its help desk verification procedures or adding additional friction to MFA prompts for these specific high-risk users?</p>
]]></description><link>https://xploitlk.com/topic/255/fake-it-calls-target-executives-in-microsoft-365-data-theft-and-extortion-attacks</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:09:59 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/255.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 00:30:26 GMT</pubDate><ttl>60</ttl></channel></rss>