IT help-desk vishing tricks executives into handing over Microsoft 365 access

Sep 08, 2026 - 14:15
IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the activity under the name PREY-0058 and notes it shares significant tradecraft similarities with a data extortion group that Google Threat Intelligence Group calls UNC6671. The extortion side has gone by several names, among them BlackFile, Pink, Helix, … More

The post IT help-desk vishing tricks executives into handing over Microsoft 365 access appeared first on Help Net Security.