Act
active
Vishing + AitM Campaign Targets Executives for M365 Data Theft
- Engineer — Plan: Enforce phishing-resistant MFA (FIDO2) for all executive accounts and audit conditional access policies to block residential-proxy sign-ins; no active PoC or KEV signal, but AitM token theft bypasses standard MFA.
- SOC/IR — Act: Hunt for anomalous M365 sign-ins from residential proxy ranges targeting director/VP accounts, especially preceded by IT help-desk call activity; tune detections for impossible-travel or token-replay events in your SIEM.
- Leader — Act: Brief executive staff on IT impersonation vishing tactics this week and confirm your help-desk verification procedures prevent social-engineering escalation; this campaign explicitly targets directors and VPs and is likely to surface as a board question.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.