Vishing Attacks Target Executives for Microsoft 365 Data Theft

Vishing Attacks Target Executives for Microsoft 365 Data Theft

First seen 8 Sep 2026, 12:03 UTC ThehackernewsHelpnetsecuritygithub.com 66.0

Article Content

Browse articles
ThreatCluster

A wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts has emerged, tracked by Arctic Wolf as PREY-0058. The attackers use vishing calls impersonating IT help desk staff to trick executives into providing credentials and multi-factor authentication (MFA) approvals. This method involves adversary-in-the-middle (AiTM) attacks, where attackers capture session tokens for unauthorized access. The primary targets are directors and vice presidents across various sectors, including healthcare, finance, and real estate. The attack infrastructure has been linked to residential proxies, specifically NodeMaven. Arctic Wolf notes that the extortion group Cinder may be a rebranding of Pink, with overlapping victim lists. Organizations are advised to implement stronger Conditional Access policies and phishing-resistant MFA solutions to mitigate these threats.

Key Points: • Attackers impersonate IT staff to gain access to Microsoft 365 accounts. • Targets include executives in sectors like healthcare and finance. • Organizations should enhance security measures against vishing and AiTM attacks.

Ask AI about this cluster

Timeline

2026-09-07
Threat cluster PREY-0058 identified
Arctic Wolf disclosed a widespread data theft and extortion campaign targeting Microsoft 365 users through vishing and AiTM techniques.
The Hacker News
2026-09-08
Details of attack methods published
Helpnetsecurity reported on the use of vishing calls and adversary-in-the-middle attacks to steal credentials and session tokens from victims.
Helpnetsecurity