Help‑desk vishing fuels Microsoft 365 token theft
📣 Threat hunters warn of a broad data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms via help‑desk vishing, adversary‑in‑the‑middle token theft, and residential‑proxy sign‑ins. Tracked by Arctic Wolf as PREY‑0058 and linked to activity groups like UNC6671 and Cinder, the actors impersonate IT staff to lure executives to authentication‑themed pages and capture MFA approvals. Attacks culminate in SharePoint, OneDrive, Exchange, and Box data exfiltration and extortion without deploying endpoint malware. Organizations are urged to adopt Conditional Access, phishing‑resistant MFA, and tighter SharePoint access controls.