Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Ireland hails EU tax agreement on carbon imports and electronic waste – POLITICO

    September 7, 2026

    A Reform UK without Nigel Farage used to be unthinkable. Not any more | Gaby Hinsliff

    September 7, 2026

    UK begins talks to rejoin EU security missions after Brexit

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Ireland hails EU tax agreement on carbon imports and electronic waste – POLITICO
    • A Reform UK without Nigel Farage used to be unthinkable. Not any more | Gaby Hinsliff
    • UK begins talks to rejoin EU security missions after Brexit
    • Best Tech Labor Day Sales I’d Shop Myself (2026): Vacuums, Headphones, and More
    • Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
    • XRP lending model reveals a 20-fold vault-loss gap
    • Tanzanian President Samia’s husband dies in hospital
    • Ratko Mladić funeral exposes gap between Serbia’s EU ambitions and political reality – POLITICO
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 07, 2026Phishing / Identity Security

    Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.

    The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671.

    It also said that the data extortion threat actor known as Cinder likely represents yet another rebrand or a possible continuation of Pink operations, citing overlaps between organizations listed on the Cinder leak site and those connected to Pink.

    It’s worth noting that the ever-evolving labels do not correspond to a single proven actor identity, but rather an amorphous set of affiliates, splinter crews, or groups using the same underlying phishing infrastructure, as indicated by Google early last month.

    Cybersecurity

    Attack chains begin with the threat actors impersonating internal IT or help desk personnel in phone calls and directing prospective targets to an authentication-themed URL that follows the pattern: .. Some of the lure domains flagged by Arctic Wolf are listed below –

    • assignpasskey[.]com
    • mfaregister[.]com
    • nowsso[.]com
    • oskeysetup[.]com
    • oursso[.]com
    • passkey-mfa[.]com
    • passkeydeploy[.]com
    • registermymfa[.]com
    • setpasskey[.]com

    The attacks lead to an operator-controlled AitM Microsoft 365 login flow that’s designed to harvest credentials and multi-factor authentication (MFA) approvals to obtain access to authenticated session tokens. The captured tokens are subsequently leveraged in session replay attacks originating from proxy infrastructure, such as NodeMaven, and from IP addresses that resolve to the same geographical location and ASN as the victim.

    “Initial sign-in activity involves applications such as ‘My Signins,’ ‘My Profile,’ ‘My Apps,’ which reveal account details and the applications available to the victim,” researchers Steven Campbell, Trevor Daher, Stefan Hostetler, and Joshua Riccio said in an analysis.

    “After initial access, the threat actors perform discovery techniques against SharePoint and Entra ID. SharePoint discovery includes SearchQueryPerformed events with contentclass:STS_Site, contentclass:STS_Web, and wildcard searches using indexdocid for pagination.”

    In the final step, the threat actors perform en masse collection and exfiltration from SharePoint, OneDrive, Exchange, and Box, after which extortion demands are sent to victims.

    Cybersecurity

    What’s notable about PREY-0058 is the absence of endpoint malware deployment or network-based lateral movement. Further analysis of subdomains across the lure infrastructure has uncovered hundreds of entries impersonating real companies.

    The targets are spread across the U.S., primarily in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.

    To counter the threat, organizations are advised to implement Conditional Access policies, deploy phishing-resistant MFA, restrict the scope of data that users have access to in SharePoint, and educate employees and help desk staff about vishing risks.

    “Defenders can disrupt this activity by detecting anomalous residential-proxy token replay, SharePoint discovery and bulk access, mailbox harvesting, and newly registered authentication-themed lure infrastructure,” Arctic Wolf said.

    attacks Calls data executives extortion Fake Microsoft Target theft
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    Fake images of Portsmouth small boats protest circulate online – Full Fact

    Mathspace discloses data breach affecting over 1 million people

    Bentley’s Torcal EV tries to balance authenticity with fake V8 sounds

    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Ireland hails EU tax agreement on carbon imports and electronic waste – POLITICO

    September 7, 2026

    A Reform UK without Nigel Farage used to be unthinkable. Not any more | Gaby Hinsliff

    September 7, 2026

    UK begins talks to rejoin EU security missions after Brexit

    September 7, 2026

    Best Tech Labor Day Sales I’d Shop Myself (2026): Vacuums, Headphones, and More

    September 7, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Ireland hails EU tax agreement on carbon imports and electronic waste – POLITICO

    September 7, 2026

    A Reform UK without Nigel Farage used to be unthinkable. Not any more | Gaby Hinsliff

    September 7, 2026

    UK begins talks to rejoin EU security missions after Brexit

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.