importantSYS.SOURCE: The Hacker News• 2026-09-07T21:21:56+05:30
Microsoft 365 Executive Targeted by Vishing and Token Theft Attacks
Threat actors are targeting Microsoft 365 executives through vishing attacks and AitM token theft to exfiltrate data and demand extortion, using residential proxies and fake authentication domains. Organizations are advised to implement phishing-resistant MFA and Conditional Access policies to mitigate the risk.
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
The activity, which mainly singles out directors, vice presidents, and other executive staff
*** END OF TRANSMISSION ***