type: incident ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [incident, vishing, phishing, extortion, microsoft-365, unc6671] ยท confidence: high ยท affected_sectors: [technology, finance, legal] ยท au_impact: true
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion
Researchers documented an identity-phishing cluster โ tracked as PREY-0058, aligned with UNC6671 โ conducting fake-IT-helpdesk vishing campaigns targeting senior executives, leading to Microsoft 365 data theft and extortion.
| Attribute | Detail |
|---|---|
| Vector | Vishing (fake IT helpdesk) |
| Target | Senior executives |
| Outcome | M365 data theft and extortion |
| Tracking | PREY-0058 (aligned with UNC6671) |
| Source | The Hacker News โ Tier 2/4 |
The cluster monetises the same identity/MFA weakness as BigBear 2.0's phishing-as-a-service โ session hijack and token theft rather than brute-forcing. It reinforces the need for phishing-resistant (FIDO2/passkey) authentication and scrutiny of credential-reset or help-desk calls.
Related Pages
- Unc6671 Vishing Attacks Target Personal Phones To Steal Saas Data โ the broader UNC6671 vishing campaign