Cookie Consent by Free Privacy Policy Generator

Microsoft 365 Users Targeted Through Fake IT Help Desk Calls and Token Theft

Threat intelligence researchers have published details of a widespread campaign targeting Microsoft 365 users through fake IT help desk calls, credential theft and session hijacking. The Hacker News reports that attackers are specifically targeting directors, vice presidents and other senior staff, using vishing calls that impersonate internal IT support to convince victims to approve multi-factor authentication prompts or provide access codes. Once initial access is gained, attackers use adversary-in-the-middle techniques to steal session tokens, then connect through residential proxy networks to make their access appear legitimate. The goal is data theft and extortion, with attackers exfiltrating email, files and other sensitive information before demanding payment.

Why this matters for UK organisations

This reflects a broader shift in how Microsoft 365 environments are being compromised. Traditional phishing emails are increasingly being supplemented or replaced by direct voice calls that feel more urgent and convincing, particularly when the caller has already gathered enough information about the target to sound credible. The use of residential proxies makes it harder for conditional access policies to detect suspicious sign-ins, because the attacker's connection appears to come from a normal home or business internet connection rather than a data centre or VPN. For UK organisations, this highlights the importance of making sure that help desk verification processes work in both directions, that users know how to verify who is calling them, and that session token protections and monitoring are in place. Senior staff are particularly attractive targets because they typically have access to more sensitive information and may be more likely to receive urgent IT support calls.

What to review

Review how your organisation verifies identity during support calls, particularly when those calls involve password resets, MFA approvals or access changes. Consider implementing a callback verification process where users are given a known internal number to call back rather than completing sensitive actions during an inbound call. Check whether your conditional access policies account for session token theft, including monitoring for unusual data access patterns, bulk downloads or access to sensitive resources even when sign-ins appear geographically normal. Review whether your security awareness training covers vishing and help desk impersonation, and whether users know what questions they should ask before complying with urgent IT requests. Consider whether monitoring is in place to detect unusual data exfiltration patterns, particularly from executive or senior staff accounts.

Source: The Hacker News

News and blog posts
Today's brief reflects a recurring theme across several areas of security...
The National Cyber Security Centre has published new guidance explaining the...
Threat intelligence researchers have published details of a widespread campaign...
Managed service provider software vendor N-able has released an emergency...