Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Executive Summary
Threat hunters revealed a widespread data‑theft and extortion campaign that targets Microsoft 365 and other SaaS services. Attackers use IT help‑desk vishing to trick executives, then employ adversary‑in‑the‑middle token theft and residential‑proxy sign‑ins to steal credentials and exfiltrate data. The campaign focuses on directors, vice presidents, and other senior staff.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-07T15:51:56+00:00 - Category: threat-intel
Original Description: Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff
"I have been impressed with the urgency of doing. Knowing is not enough; we must apply. Being willing is not enough; we must do."
— Leonardo da Vinci