CuraSec

Act active

Vishing + AitM Campaign Targets Executives for M365 Data Theft

2026-09-07 16:27 UTC · The Hacker News · read the source ↗ #vishing#aitm#microsoft-365
  • Engineer — Plan: Enforce phishing-resistant MFA (FIDO2) for all executive accounts and audit conditional access policies to block residential-proxy sign-ins; no active PoC or KEV signal, but AitM token theft bypasses standard MFA.
  • SOC/IR — Act: Hunt for anomalous M365 sign-ins from residential proxy ranges targeting director/VP accounts, especially preceded by IT help-desk call activity; tune detections for impossible-travel or token-replay events in your SIEM.
  • Leader — Act: Brief executive staff on IT impersonation vishing tactics this week and confirm your help-desk verification procedures prevent social-engineering escalation; this campaign explicitly targets directors and VPs and is likely to surface as a board question.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.