Fake IT Help Desk Calls Used to Hijack Microsoft 365 Executive Accounts
What Happened
Threat hunters have disclosed a widespread data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms. According to the report, attackers combine IT help desk vishing (voice phishing) with adversary-in-the-middle (AitM) token theft and sign-ins routed through residential proxies. The activity primarily targets directors, vice presidents, and other executive staff.
Why It Matters
Executives typically hold broad access to sensitive email, files, and SaaS admin functions, making them high-value targets for data theft and extortion. By impersonating IT help desk staff over the phone, attackers can bypass technical defenses entirely and manipulate a human into resetting credentials or approving MFA — and AitM token theft allows session hijacking even where MFA is otherwise enforced. Routing logins through residential proxies helps the resulting sign-ins blend in with legitimate user traffic, undermining geolocation- and ASN-based anomaly detection.
What Defenders Should Watch For
- Review and harden help desk identity-verification procedures for password resets and MFA changes, especially for executive and privileged accounts.
- Hunt for anomalous Microsoft 365 sign-ins from residential/consumer ISP IP ranges, particularly following a recent password reset or MFA re-registration.
- Monitor for AitM indicators: token replay, session cookie reuse, sign-ins with unusual token issuance patterns, or logins from new devices immediately after a help desk interaction.
- Correlate help desk tickets/call logs with subsequent account changes to spot social-engineering-driven resets.
- Consider phishing-resistant authentication (FIDO2/WebAuthn) for executives to reduce exposure to AitM token theft.
Developing Intel
This is a developing threat cluster and details may evolve as more is reported. This post reflects the facts as currently disclosed; for the full account, see the original report at The Hacker News.