[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKSBmJLZZBYPf84cHhKU2u7z65cBtY0r14y5IBCtK5oA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"f6054fc9-01d9-40dd-97d3-6546c40d098b","vishing-attacks-exploit-human-trust-to-hijack-saas-credentials-and-mfa","23716e48-76b8-4e0b-9fca-eb174ae93c79","Vishing Attacks Exploit Human Trust to Hijack SaaS Credentials and MFA","UNC6671 demonstrates how sophisticated social engineering via phone calls can bypass technical controls entirely by targeting the human element. By impersonating IT staff and directing employees to adversary-in-the-middle phishing portals, attackers capture both passwords and real-time MFA tokens before the victim realizes anything is wrong. This matters because once SaaS platforms like Microsoft 365 and Okta are compromised, attackers gain broad access to sensitive organizational data with legitimate credentials, making detection extremely difficult. The attack highlights that MFA alone is insufficient when users can be manipulated into surrendering tokens in real time.","**Immediate actions:**\n- Train all employees to never provide credentials or MFA codes over the phone, even to callers claiming to be internal IT staff.\n- Implement phishing-resistant MFA methods (e.g., FIDO2\u002Fpasskeys) that cannot be replayed by adversary-in-the-middle infrastructure.\n- Establish a verified IT callback procedure so employees can confirm the identity of any caller requesting sensitive actions.\n\n**Long-term improvements:**\n- Deploy Conditional Access Policies in SaaS platforms to restrict logins from unexpected geolocations, devices, or network ranges.\n- Enforce a Zero Trust architecture requiring continuous verification of identity and device posture before granting SaaS access.\n- Conduct regular vishing simulation exercises targeting high-risk departments such as finance and HR.\n\n**Detection measures:**\n- Enable SIEM alerting on anomalous SaaS login events, including impossible travel, new device registrations, and bulk data downloads.\n- Monitor Okta and Microsoft 365 audit logs for large-scale data exports or OAuth token grants to unfamiliar applications.\n- Integrate threat intelligence feeds for known AiTM infrastructure indicators to block malicious proxy domains at the perimeter.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 14 – Security Awareness and Skills Training","CIS Control 6 – Access Control Management","CIS Control 10 – Malware Defenses","NIST SP 800-63B – Authentication and Lifecycle Management","NIST AC-2 – Account Management","NIST AC-17 – Remote Access","NIST SI-3 – Malicious Code Protection","NIST SP 800-177 – Trustworthy Email (phishing guidance)","MITRE ATT&CK T1566.004 – Phishing: Vishing","MITRE ATT&CK T1539 – Steal Web Session Cookie","GDPR Article 32 – Security of Processing","NIST CSF PR.AT-1 – Awareness and Training","NIST CSF DE.CM-3 – Personnel Activity Monitoring","published","2026-08-07T20:21:12.521721+00:00","2026-08-07T20:21:12.234+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Func6671-vishing-attacks-target-personal.html","unc6671-vishing-attacks-target-personal-phones-to-steal-saas-data-37859b","UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[52],{"id":53,"date":54,"edition":55,"title":56,"audio_url":57},"27e65655-5449-450a-9bb0-0a47fae669b6","2026-08-08","morning","ThreatNoir Weekend Brief — August 8","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-08\u002Fthreatnoir-morning-brief-2026-08-08.mp3"]