Recent disclosures by threat hunters reveal a sophisticated threat cluster focused on stealing data and extorting organizations via targeted vishing attacks. Specifically aimed at high-ranking officials such as directors and vice presidents, these attacks leverage IT help desk impersonation tactics to gain access to Microsoft 365 and other SaaS platforms. Techniques employed include adversary-in-the-middle (AitM) token theft and the use of residential proxies to mask malicious activities, thereby complicating detection efforts.
The implications for businesses are significant, as the targeting of executive-level personnel suggests that attackers are keenly aware of the access and sensitive information these individuals control. Organizations must enhance their cybersecurity protocols by implementing robust training programs to educate executives about such social engineering tactics. Additionally, businesses should consider deploying multi-factor authentication, monitoring for anomalous login attempts, and establishing strict verification processes for IT requests. This emerging threat underscores the urgent need for enhanced vigilance and proactive measures in cybersecurity frameworks, particularly as more organizations rely on cloud-based services like Microsoft 365.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html)*