BPO Firms Targeted in Sophisticated Phishing Campaign Bypassing MFA
UNC6783 successfully compromised business process outsourcing firms through multi-layered social engineering attacks that included spoofed login pages, clipboard-stealing phishing kits, and fake security updates. The threat actor specifically targeted BPOs because they handle sensitive data for multiple high-value corporate clients, making them attractive targets for data theft. Most critically, the attackers were able to bypass multi-factor authentication through sophisticated phishing techniques, demonstrating that MFA alone is insufficient protection against determined adversaries. This incident highlights how third-party service providers can become entry points for accessing sensitive corporate data from multiple organizations simultaneously.
Tactical Insight
Immediate actions
- Deploy phishing-resistant MFA methods like FIDO2 security keys or certificate-based authentication
- Implement email security solutions with advanced threat protection and URL sandboxing
- Conduct emergency security awareness training focused on current phishing techniques
Long-term improvements
- Establish zero-trust architecture with continuous verification for all access requests
- Implement application allowlisting to prevent execution of unauthorized software updates
- Develop comprehensive third-party risk management programs for all BPO relationships
Detection measures
- Monitor for suspicious clipboard access and unusual authentication patterns
- Deploy endpoint detection and response tools to identify remote access malware
- Establish security information sharing agreements with BPO partners for threat intelligence