[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fN4dzsHHww2f_K9ummS1BGKbT46FVBYyE4jQ90ClxoMY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":28,"created_at":29,"published_at":30,"article":31,"tags":35,"podcasts":54},"fc9c26d8-eb28-46b0-a941-589067b307b4","vishing-token-theft-campaign-targets-executives-via-fake-it-calls","cc3b9a72-1ec4-482a-9685-5ca4abb2049f","Vishing & Token Theft Campaign Targets Executives via Fake IT Calls","PREY-0058 exploits human trust by impersonating IT support staff over the phone, tricking executives into approving MFA prompts and surrendering session tokens — bypassing traditional credential-based defenses entirely. Once attackers obtain valid session tokens through Adversary-in-the-Middle (AitM) techniques, they gain persistent, authenticated access to Microsoft 365, SharePoint, OneDrive, and Box without needing passwords again. Executives are high-value targets because they typically hold broad data access and are less likely to be questioned when accessing sensitive files. The subsequent extortion phase compounds the damage, turning a data breach into a financial and reputational crisis. This attack highlights that MFA alone is insufficient when social engineering manipulates users into approving fraudulent authentication requests.","**Immediate actions:**\n- Train executives and their assistants to verify IT support requests through a known, out-of-band callback number before approving any MFA prompts.\n- Deploy phishing-resistant MFA (e.g., FIDO2\u002Fpasskeys) to eliminate approval-based MFA methods vulnerable to vishing and AitM attacks.\n- Block or flag sign-ins originating from residential proxy IP ranges using Conditional Access policies in Microsoft Entra ID.\n\n**Long-term improvements:**\n- Implement Privileged Access Workstations (PAWs) and strict Conditional Access policies that restrict executive account access to known, managed devices and locations.\n- Apply least-privilege data access controls so that even compromised executive sessions cannot bulk-exfiltrate from SharePoint, OneDrive, and Exchange.\n- Establish a verified IT support helpdesk protocol with unique employee callback codes to authenticate internal support staff to end users.\n\n**Detection measures:**\n- Monitor for anomalous session token usage, including sign-ins from unexpected geographies or residential proxy ASNs following a successful MFA approval.\n- Enable Microsoft 365 Defender alerts for bulk file downloads from SharePoint and OneDrive, and integrate these with your SIEM for rapid triage.\n- Conduct regular threat-hunting exercises specifically looking for AitM infrastructure indicators (e.g., Evilginx-style reverse proxies) targeting your domain.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","CIS Control 16 – Application Software Security","NIST SP 800-63B – Digital Identity Guidelines (Phishing-Resistant AAL3 Authenticators)","NIST AC-2 – Account Management","NIST AC-17 – Remote Access","NIST SI-4 – System Monitoring","NIST IR-6 – Incident Reporting","MITRE ATT&CK T1566.004 – Phishing: Vishing","MITRE ATT&CK T1539 – Steal Web Session Cookie","MITRE ATT&CK T1567 – Exfiltration Over Web Service","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","NIST CSF DE.CM-1 – Network Monitoring","NIST CSF PR.AC-7 – Strong Authentication","published","2026-09-07T18:20:45.263862+00:00","2026-09-07T18:20:45.153+00:00",{"id":7,"url":32,"slug":33,"title":34},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fmicrosoft-365-attackers-use-help-desk.html","fake-it-calls-target-executives-in-microsoft-365-data-theft-and-extortion-attack-9c92a7","Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks",[36,42,48],{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":49,"name":50,"slug":51,"description":52,"color":53},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[55],{"id":56,"date":57,"edition":58,"title":59,"audio_url":60},"5a39d630-1518-4eb0-9881-93c489abf775","2026-09-08","morning","ThreatNoir Morning Brief — September 8","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-08\u002Fthreatnoir-morning-brief-2026-09-08.mp3"]