Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [incident, vishing, phishing, extortion, microsoft-365, unc6671] ยท confidence: high ยท affected_sectors: [technology, finance, legal] ยท au_impact: true

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion

Researchers documented an identity-phishing cluster โ€” tracked as PREY-0058, aligned with UNC6671 โ€” conducting fake-IT-helpdesk vishing campaigns targeting senior executives, leading to Microsoft 365 data theft and extortion.

Attribute Detail
Vector Vishing (fake IT helpdesk)
Target Senior executives
Outcome M365 data theft and extortion
Tracking PREY-0058 (aligned with UNC6671)
Source The Hacker News โ€” Tier 2/4

The cluster monetises the same identity/MFA weakness as BigBear 2.0's phishing-as-a-service โ€” session hijack and token theft rather than brute-forcing. It reinforces the need for phishing-resistant (FIDO2/passkey) authentication and scrutiny of credential-reset or help-desk calls.

Related Pages

Source