discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters disclose a data theft and extortion threat targeting Microsoft 365 and SaaS users through fake IT calls and proxy sign-ins.

By Ravie Lakshmanan·Sep 7·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Image: thehackernews.com

Threat actors impersonate IT help desk personnel to trick executives into providing credentials, leading to data theft and extortion demands.

Why it matters

This threat highlights the vulnerability of executives to phishing and the importance of robust security measures in SaaS environments.

Bad guys pretend to be IT people on the phone and trick executives into giving them their login info. They use fake websites and special codes to get into the executives' accounts and steal their data. Then they send the executives a message asking for money.

Analysis

Attack Mechanisms

The attackers use fake IT calls to direct executives to authentication-themed URLs, which lead to operator-controlled AitM flows for credential harvesting. Proxy infrastructure is used to replay session tokens.

Impact and Countermeasures

The threat primarily affects executives in various industries, including construction, healthcare, and finance. Organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, and educate employees about vishing risks.

Subdomains and Target Spread

Subdomains impersonating real companies have been identified, with targets spread across the U.S., particularly in construction and healthcare sectors.

Conclusion

The threat underscores the need for robust security measures and employee education to mitigate the risk of data theft and extortion attacks.

Key points

  • Threat actors impersonate IT help desk personnel to trick executives into providing credentials.
  • The attackers use fake IT calls and proxy sign-ins to steal data and extort executives.
  • Targets are primarily executives in construction, healthcare, and finance industries.
The Upside

By improving security measures and educating employees, organizations can prevent these fake calls and protect their executives' data.

The Downside

If organizations don't take these security measures seriously, the threat actors can still trick executives and steal their data.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecurityphishingexecutivedata-theft

Author

Ravie Lakshmanan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 7, 2026

Source

thehackernews.com

Share

Topics

securitycybersecurityphishingexecutivedata-theft

Related

More from this desk

Sep 7·bleepingcomputer.com

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento zero-day vulnerability exploited to deploy Linux backdoor. Adobe Enterprise Support working on fix.

Sep 7·bleepingcomputer.com

Trezor data breach impact now reaches 81,000 customers

Trezor expands data breach affecting 81,000 customers, including full names, addresses, emails, and phone numbers. ShipMonk failed to delete exposed data as required by contract.

Sep 7·thehackernews.com

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers found three incidents using different methods to activate a four-stage VBScript chain that leads to rogue ScreenConnect installations.

Sep 7·bleepingcomputer.com

ChatGPT can now connect to your personal apps to mimic writing style

OpenAI testing Writing Style feature for ChatGPT that learns writing style from connected apps