highPhishing

Help Desk Vishing & AitM Token Theft Campaign Targeting Microsoft 365 Executives

First seen Sep 8, 2026 · Updated Sep 8, 2026

vishingsocial-engineeringMicrosoft 365AitMtoken-theftSaaSexecutive-targetingextortionresidential-proxyagent-relevant

A threat cluster is targeting executives (directors, VPs, senior staff) at organizations using Microsoft 365 and other SaaS platforms through IT help desk vishing calls, adversary-in-the-middle (AitM) session token theft, and sign-ins routed through residential proxy networks to evade geolocation-based detection. Stolen credentials and session tokens are used for data exfiltration followed by extortion demands. The campaign leverages human trust in IT support workflows rather than software exploits, making it effective against organizations with strong technical controls but weaker identity-verification processes.

Technical Analysis

Attackers impersonate internal IT help desk staff via voice phishing to convince executives to reset credentials or approve MFA prompts, then use AitM proxy infrastructure to intercept authentication flows and steal session tokens, bypassing MFA entirely. Residential proxy services are used to make fraudulent Microsoft 365 sign-ins appear to originate from legitimate geographic locations and ISPs, evading conditional access and impossible-travel detections. Once inside, attackers access SharePoint, OneDrive, Exchange Online, and other SaaS data stores to exfiltrate sensitive files before issuing extortion demands. No software vulnerability or CVE is involved; this is a pure identity and social-engineering attack chain targeting cloud identity providers. Organizations running AI agents or automation that authenticate against Microsoft 365 via OAuth tokens, service accounts, or delegated permissions face heightened risk, since stolen session tokens or compromised executive credentials could grant attackers access to connected agent pipelines, RAG data sources, or API keys stored in M365-integrated tooling.

Affected Systems

Microsoft 365 (Exchange Online, SharePoint, OneDrive, Teams), Entra ID (Azure AD) authentication flows, other SaaS platforms with SSO/MFA reliant on session tokens, IT help desk identity verification processes

Indicators of Compromise

  • Specific IOCs not disclosed in source reporting; indicators typically include: anomalous MFA reset requests originating from help desk-impersonation calls, sign-ins from residential proxy IP ranges inconsistent with user's normal location, AitM reverse-proxy phishing domains mimicking Microsoft login portals, and unusual OAuth token reuse across disparate IP addresses

Remediation Steps

  1. 1

    Strengthen help desk identity verification

    Require multi-factor, out-of-band verification (e.g., callback to a known number, manager confirmation) before processing password resets or MFA changes requested by phone.

  2. 2

    Enforce phishing-resistant MFA

    Deploy FIDO2/WebAuthn hardware keys or platform authenticators for executives and privileged accounts to prevent AitM token theft.

  3. 3

    Monitor for anomalous sign-in patterns

    Use Conditional Access and identity protection tools to flag sign-ins from residential proxy/VPN ranges, impossible travel, and new device fingerprints.

  4. 4

    Implement token binding and session controls

    Enable continuous access evaluation and shorten token lifetimes to reduce the window of usability for stolen session tokens.

  5. 5

    Audit and restrict OAuth app permissions

    Review third-party and agent/automation OAuth grants against Microsoft 365 to ensure compromised executive accounts cannot cascade access into connected AI agent or API integrations.

  6. 6

    Conduct executive-focused security awareness training

    Train high-value targets specifically on help desk vishing tactics and establish clear internal protocols for verifying IT support requests.

Industries Most Exposed

Corporate enterprisesfinancial servicestechnologyprofessional servicesany organization using Microsoft 365 with executive leadership as high-value targets

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.