Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters disclose a data theft and extortion threat targeting Microsoft 365 and SaaS users through fake IT calls and proxy sign-ins.
Intelligence analysis by Qwen 2.5 (3B)

Threat actors impersonate IT help desk personnel to trick executives into providing credentials, leading to data theft and extortion demands.
Bad guys pretend to be IT people on the phone and trick executives into giving them their login info. They use fake websites and special codes to get into the executives' accounts and steal their data. Then they send the executives a message asking for money.
Analysis
Attack Mechanisms
The attackers use fake IT calls to direct executives to authentication-themed URLs, which lead to operator-controlled AitM flows for credential harvesting. Proxy infrastructure is used to replay session tokens.
Impact and Countermeasures
The threat primarily affects executives in various industries, including construction, healthcare, and finance. Organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, and educate employees about vishing risks.
Subdomains and Target Spread
Subdomains impersonating real companies have been identified, with targets spread across the U.S., particularly in construction and healthcare sectors.
Conclusion
The threat underscores the need for robust security measures and employee education to mitigate the risk of data theft and extortion attacks.
Key points
- Threat actors impersonate IT help desk personnel to trick executives into providing credentials.
- The attackers use fake IT calls and proxy sign-ins to steal data and extort executives.
- Targets are primarily executives in construction, healthcare, and finance industries.
By improving security measures and educating employees, organizations can prevent these fake calls and protect their executives' data.
If organizations don't take these security measures seriously, the threat actors can still trick executives and steal their data.



