Fake IT Calls Drive M365 Exec Data Theft Campaign
Threat hunters have disclosed an active data theft and extortion cluster targeting Microsoft 365 executives via vishing: fake IT help desk calls that harvest credentials and SaaS access.

Active. Threat hunters have disclosed a widespread data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms. Vector: fake IT help desk calls placed to executives, per The Hacker News. Published September 7.
The technique is phone-based social engineering: attackers impersonate internal IT support or vendor help desks, reach executives directly, and walk them through steps that hand over credentials or SaaS session access. M365 is the primary target but the disclosed campaign hits other SaaS platforms as well.
Confidence on execution: high (published threat-hunter research). Confidence on full campaign scope: unconfirmed — the Hacker News report does not name a specific threat group or specify the number of victim organizations.
Data theft and extortion follow the initial access. The pattern is consistent with callback phishing and vishing techniques documented in other 2026 campaigns. The same credential-theft-to-extortion loop appeared in the JSCeal campaign targeting Google auth cookies and in earlier abuse of Entra ID weaknesses — different access methods, same destination.
No CVEs are involved. This is a social engineering campaign; technical controls on M365 configuration do not block a person who calls your executives and talks their way in.
What the research confirms:
- Executives are the primary target, not general staff
- Microsoft 365 is the primary platform, other SaaS in scope
- Data theft is followed by extortion demands
What remains unconfirmed: threat group attribution, victim count, and whether the extortion step involves file encryption or is purely data-leak-based.
Relevant defensive context: MFA app-based approval requests are exploitable through push fatigue if a caller is simultaneously triggering them. Number-matching MFA and out-of-band IT verification procedures reduce that surface. Those are controls, not guarantees.
Full disclosure from The Hacker News is linked here.
Found this useful? Share it.


