< ciso
brief />
Tag Banner

All news with #vishing tag

41 articles

Help‑desk vishing fuels Microsoft 365 token theft

📣 Threat hunters warn of a broad data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms via help‑desk vishing, adversary‑in‑the‑middle token theft, and residential‑proxy sign‑ins. Tracked by Arctic Wolf as PREY‑0058 and linked to activity groups like UNC6671 and Cinder, the actors impersonate IT staff to lure executives to authentication‑themed pages and capture MFA approvals. Attacks culminate in SharePoint, OneDrive, Exchange, and Box data exfiltration and extortion without deploying endpoint malware. Organizations are urged to adopt Conditional Access, phishing‑resistant MFA, and tighter SharePoint access controls.
read more →

Revolut-targeted phone scams hit Jersey residents

📞 Police in Jersey warn residents to be vigilant after a spike in phone scams targeting Revolut accounts. Over a four-week period, 75% of reported scam incidents involved Revolut, with victims losing roughly £180,000. Callers impersonate bank staff, request security details, or ask victims to transfer funds to purportedly "safe" accounts. Revolut urges customers to use its secure in-app chat and never share passwords; police remind the public to report suspected fraud.
read more →

Spring Ring: Voice Phishing Through Collaboration Tools

🛡️ Between January and April 2026, Unit 42 uncovered a coordinated vishing operation—named Spring Ring—using external Microsoft Teams accounts to impersonate IT help desk staff. The attackers contacted over 150 employees across at least 10 companies and employed live voice calls to coerce victims into installing RMM tools or custom malware. Two distinct campaigns were observed: one delivering an obfuscated PowerShell RAT and another using tailored executables that attempted NTLM relay attacks against domain controllers.
read more →

Large-Scale Debt-Relief Phishing Campaign Blocked

📧 Check Point detected and blocked a widespread email phishing campaign that used fraudulent debt-relief and financial hardship offers to trick recipients into calling attacker-controlled phone numbers. Over 14 days, about 24,700 messages targeted users at more than 9,000 organizations, highlighting phishing tactics that rely on social engineering and phone-based conversion rather than malicious links or attachments. Check Point Email Security uses AI, threat intelligence, and intent analysis to stop such campaigns before users engage.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

Levi Strauss reports corporate data theft after breach

🔒 Levi Strauss & Co. disclosed that attackers used social engineering on three employees to access company-issued machines and exfiltrate corporate data. The company says rapid response contained the intrusion and no consumer data was impacted, with no disruption to business operations. An investigation is ongoing and Levi’s will provide additional notifications as required; some reporting links the incident to voice-phishing campaigns.
read more →

UNC6671 Targets Financial and Cloud Environments

🔎 GTIG reports UNC6671 continues active compromises and data-theft extortion despite the alleged BlackFile retirement, diversifying into Redact, Pink, Helix, and Falcon. The actor uses targeted voice phishing (vishing) to lure employees—often on personal phones—to spoofed login portals with AiTM infrastructure to harvest credentials and MFA tokens, then deploys scripts to exfiltrate data from enterprise cloud apps like Microsoft 365 and Okta. The update details infrastructure linkages, evolving targeting focused on financial services and private equity, and offers hardening guidance to mitigate these identity-centric threats.
read more →

Health-ISAC warns of rising ShinyHunters data theft

🔒 Health-ISAC warns healthcare and medtech organizations of an uptick in successful attacks by the extortion group ShinyHunters, which leverages supply-chain and identity attacks to breach cloud SaaS and storage platforms. Attacks commonly begin with vishing and social engineering to compromise SSO accounts (Okta, Microsoft Entra, Google), granting access to services like Salesforce, Microsoft 365, SharePoint, and others. The advisory urges hardening helpdesk and SSO procedures, adopting phishing-resistant MFA, treating SSO as Tier 0, and centralizing audit logs to detect large-scale cloud data theft.
read more →

Microsoft maps year-long OAuth access campaigns

🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more →

Defending SaaS OAuth Abuse Targeting Salesforce

🔒 Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more →

Police point to Dutch suspects in Odido breach

🔎 The Dutch National Police report strong indications that Dutch-speaking attackers were involved in the February breach of telecom provider Odido. Investigators recovered traces including a phone call where an impersonator posing as an Odido IT employee used social engineering to enable a phishing-based data theft. Odido disclosed the incident affected millions of customers and that exposed records may include names, addresses, contact details, IBANs, and some ID numbers, while call records, billing data and passwords were not exposed. The extortion group ShinyHunters claimed responsibility and released a large archive of stolen records, and the gang has been linked to multiple vishing and SSO-targeting campaigns affecting major providers.
read more →

Helix vishing group targets SharePoint data theft

🔒 A new extortion group dubbed Helix uses vishing, device-code phishing, and MFA abuse to access and exfiltrate files from SharePoint environments. Operators impersonate managers via phone calls and spoofed caller IDs to trick employees into granting access, then register authenticators for persistence and bulk-download content. ReliaQuest links Helix tactics and infrastructure to prior groups like ShinyHunters and BlackFile, and recommends disabling device-code authentication and restricting SharePoint to managed devices.
read more →

Vishing campaign abuses Entra passkey enrollment

🔔 A threat actor is using voice-based fake security calls to trick Microsoft 365 users into enrolling a malicious Entra passkey. The attacker directs victims to realistic phishing pages that mimic the Microsoft enrollment flow and uses an operator-controlled PHP kit to capture credentials and MFA responses in real time. Okta attributes the campaign to O-UNC-066, linked to the extortion group Pink, which targets multiple industries and quickly exfiltrates data after account takeover.
read more →

Shop app abused to deliver callback phishing scams

🛒 Researchers warn that threat actors are abusing Shop, Shopify’s order-tracking app, by adding fake purchase receipts to users' histories to trick them into calling scam phone numbers. Fraudulent receipts impersonate brands like Apple, PayPal, Norton, and McAfee, and aim to collect credentials, payment details, OTPs, or persuade victims to install remote access software. Users are advised to verify charges with their bank rather than call numbers on suspicious receipts.
read more →

Silent Ransom Group Targets U.S. Law Firms Now

🛡️ Mandiant reports the Silent Ransom Group (UNC3753) is targeting U.S. law firms and professional services with invoice-themed phishing followed by voice calls impersonating IT staff. Attackers use callback phishing to trick victims into installing remote support tools like AnyDesk or Zoho Assist, granting access to networks and enabling rapid data theft and extortion. The campaign involves phishing domains, self-destructing messaging, and fast-flux infrastructure to host leak sites.
read more →

Charter Communications breach exposes 4.9M accounts

🔒 The ShinyHunters extortion gang claims to have stolen personal details from 4.9 million Charter Communications accounts after a vishing attack in early April that compromised an employee's Microsoft Entra account. Charter confirmed the incident but says no sensitive PII or CPNI was exfiltrated, while Have I Been Pwned verified leaked records containing names, emails, addresses, phone numbers and some job titles. The group published stolen Salesforce data after a ransom was refused.
read more →

Charter Confirms Breach After ShinyHunters Extortion

🔒 Charter Communications confirmed a data breach after the ShinyHunters extortion group claimed to have stolen millions of customer records. The company says it is notifying authorities and maintains that No sensitive personal information (PI) or CPNI was exfiltrated. ShinyHunters alleges the intrusion began via a vishing attack that compromised an employee's Microsoft Entra account and allowed access to Salesforce data.
read more →

BlackFile (UNC6671): Vishing and SSO extortion campaign

🔐 Google Threat Intelligence Group (GTIG) details UNC6671, operating as "BlackFile," which uses large-scale voice phishing (vishing) and adversary-in-the-middle techniques to bypass MFA and compromise SSO access. The group targets Microsoft 365 and Okta, leveraging Python and PowerShell scripts to automate exfiltration and repurpose valid session cookies to "stream" files. GTIG highlights detection indicators such as python-requests User-Agent mismatches, nonstandard IP infrastructure, and subdomain-based credential-harvesting sites to aid defenders.
read more →

Vishing and SSO Abuse Drive Rapid SaaS Extortion Campaigns

🔒 Cybercrime clusters Cordial Spider and Snarky Spider are executing fast, low-footprint extortion campaigns that rely on vishing and SSO adversary-in-the-middle pages to harvest credentials and MFA codes. After registering devices and suppressing notification emails, attackers pivot directly into SaaS platforms such as Google Workspace, HubSpot, SharePoint, and Salesforce to locate and exfiltrate high-value files. Researchers note heavy use of living-off-the-land techniques and residential proxies to minimize detection.
read more →

Romanian Leader of Swatting Ring Sentenced to 4 Years

🚨 A Romanian national, Thomasz Szabo, was sentenced to four years in U.S. federal prison after pleading guilty to conspiracy and threats involving explosives. Extradited from Romania in November 2024, Szabo led an online swatting community that organized bomb threats and swatting calls beginning in late 2020 and targeting more than 75 public officials, journalists, and religious institutions. The court also ordered three years of supervised release.
read more →