Microsoft 365 Vishing Attacks: The Four Checks to Run This Week

by Rebecca Sutton

Someone calls your office claiming to be IT support. They ask a director to “verify” a Microsoft 365 login. Treat that call as an attack in progress. It is exactly how a fast-moving wave of Microsoft 365 vishing attacks is breaking into companies right now. The fix costs far less than most security projects you’ll approve this year.

Help desk staff wearing headsets at their laptops, the identity impersonated in Microsoft 365 vishing attacks

Inside the Microsoft 365 vishing attacks

Arctic Wolf researchers disclosed the campaign on 7 September. They track it as PREY-0058. The attackers phone directors, vice presidents and other senior staff directly. They claim to be internal IT. They say a security update or passkey enrolment is overdue. Then they send a link that looks like it belongs to their own company.

That link leads to a forged Microsoft 365 sign-in page. It captures the password and the multi-factor approval in real time. The attackers then reuse that session from proxy servers. Those servers are picked to match the victim’s own country and network. Google’s Mandiant team tracks a closely related cluster called UNC6671. It links to extortion brands that keep rebranding: BlackFile, Redact, Pink, Helix and Falcon.

Once inside a mailbox, the attackers don’t smash and grab. They quietly map what SharePoint, OneDrive, Exchange and Box the account can reach. They pull out anything sensitive. An extortion demand follows later. No malware ever touches a laptop, so most antivirus tools stay silent.

The fake login links follow a recognisable pattern too. Arctic Wolf’s report names domains such as assignpasskey[.]com, mfaregister[.]com and setpasskey[.]com. Each one is paired with the target company’s own name. That makes the page read like an internal passkey setup tool. This detail matters for training. Tell staff to expect this exact style of link, not just “suspicious emails” in general.

Four checks to run this week

Closing the gap behind these Microsoft 365 vishing attacks doesn’t need a big budget. You need to confirm four things are actually true, not just written in a policy somewhere.

  • A documented help desk callback process. Nobody should trust an inbound IT request during the call itself. Staff hang up. They call the help desk back on a known internal number. Then they verify the request separately.
  • Phishing-resistant MFA for anyone with wide access. A push notification a tired employee approves without reading offers little protection here. FIDO2 security keys or device-bound passkeys stop this specific technique, because the credential can’t be replayed from another device.
  • Conditional Access rules that actually challenge unusual sign-ins. If a login from an unfamiliar country or network doesn’t trigger extra verification, that’s a gap worth closing first. A zero trust approach to identity makes this the default rather than an afterthought.
  • Alerts on bulk SharePoint or mailbox access. Most organisations can already see this kind of activity in their Microsoft 365 logs. Few have anyone reviewing those logs often enough to notice a director’s account suddenly downloading hundreds of files.

Who needs to hear about this

Tell your help desk first. They’re the identity attackers copy. They’re also your best early warning system, once they know the pattern to watch for. Then brief anyone senior enough to be a worthwhile target: directors, finance leads, anyone with wide document access. Arctic Wolf’s report names construction, healthcare, real estate and professional services among the sectors already hit, alongside the hedge funds and law firms making headlines. None of that maps neatly onto “large enterprise only,” and the same Microsoft 365 vishing attacks work just as well against a fifty-person firm.

Google’s own researcher, Austin Larsen, told BleepingComputer that a single core group likely sits behind all these rebranded extortion names. Initial ransom demands have run from $1 million to $3 million. They typically settle around $750,000 once negotiations start. A smaller firm would pay a different amount, but the initial access technique costs the attacker almost nothing to attempt. Scale of target barely matters to them.

The one habit worth changing today

Most companies train staff to comply quickly when “IT” calls, because slowing that down used to just waste time. These Microsoft 365 vishing attacks show why that instinct now needs a pause button. A five-second callback to a known number costs almost nothing. A compromised executive mailbox, fully exfiltrated and held for ransom, costs a great deal more. It also takes weeks to untangle, even after the attacker is gone.

Put the callback rule in writing. Tell people it exists. Test it now and then with a mock call. That single change closes most of the door this campaign is walking through.

Testing beats assuming here. A written policy tells you nothing about whether staff will actually follow it when a confident voice calls at a busy moment. A short, planned social engineering exercise, run internally or by an outside tester, will show you exactly where the gap sits before an attacker finds it first. One successful call can lead to a six or seven figure extortion demand, so the cost of finding out in advance is easy to justify.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like