Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Arctic Wolf has linked PREY-0058 to a widespread data theft and extortion campaign that targets Microsoft 365 and other SaaS platforms using help desk vishing, AitM token theft, and residential-proxy sign-ins. The attackers focus on executives, then harvest data from SharePoint, OneDrive, Exchange, and Box before sending extortion demands, with overlaps suggesting ties to UNC6671 and possibly Cinder/Pink. #PREY0058 #UNC6671 #Cinder #Pink #Microsoft365 #SharePoint #OneDrive #Exchange #Box

Keypoints

  • PREY-0058 targets Microsoft 365 and other SaaS services through vishing and AitM token theft.
  • The campaign mainly singles out executives such as directors and vice presidents.
  • Attackers use authentication-themed lure domains to steal credentials and MFA approvals.
  • Captured session tokens are replayed through residential proxies to access victim accounts.
  • Data is collected from SharePoint, OneDrive, Exchange, and Box before extortion demands are issued.

Read More: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html