Coordinated Vishing Attacks Targeting SaaS Executives

Coordinated Vishing Attacks Targeting SaaS Executives

First seen 10 Sep 2026, 04:14 UTC Ciberseguridadlatam 66.5

Article Content

Browse articles
ThreatCluster

A coordinated campaign is targeting executives in SaaS companies, primarily using Microsoft 365, through social engineering techniques. Attackers initiate contact via phone calls posing as internal IT support, leading victims to phishing sites that capture session tokens rather than passwords. This method allows attackers to bypass multi-factor authentication (MFA) and access sensitive corporate data. The campaign has been observed to use residential proxies to mask the attacker's location, making detection difficult. The primary targets are high-ranking officials such as directors and vice presidents, who have access to strategic information. The attacks have been ongoing since at least May 2026, with a focus on organizations reliant on Microsoft 365. The threat landscape is particularly concerning in Latin America due to the widespread use of these platforms. Microsoft Security Research is actively tracking these incidents.

Key Points: • Executives in SaaS companies are primary targets of a coordinated vishing campaign. • Attackers use phone calls to impersonate IT support and capture session tokens. • The campaign has been active since May 2026, focusing on organizations using Microsoft 365.

Ask AI about this cluster

Timeline

2026-05-01
Campaign tracking began
Microsoft Security Research started monitoring a series of cloud intrusions linked to social engineering tactics.
Ciberseguridadlatam
2026-09-08
Vishing attacks documented
Researchers reported a pattern of attacks using vishing and token capture against SaaS executives.
Ciberseguridadlatam
2026-09-10
Current status of attacks
Ongoing investigations reveal a consistent attack method across multiple organizations.
Ciberseguridadlatam