Microsoft Warns of Active M365 Attacks Using Fake IT Calls to Hijack MFA and Sessions
Microsoft Security Research has disclosed a critical, active campaign in which attackers impersonate IT staff via phone calls and SMS to trick employees into compromising their Microsoft 365 accounts. Two primary techniques are used: adversary-in-the-middle (AiTM) phishing via fake authentication sites that steal session tokens, and device code flow abuse where victims unknowingly authorize attacker-controlled clients on legitimate Microsoft screens. Once access is gained, attackers register their own MFA methods to maintain persistence and use Microsoft Graph, SharePoint, OneDrive, and Exchange to enumerate and collect sensitive data. Microsoft notes that targets are likely pre-researched using public information, with initial contact made on personal phone numbers to bypass corporate security controls. Recommended mitigations include enforcing phishing-resistant MFA such as FIDO2 keys, blocking unnecessary device code flows via Conditional Access, and training users never to update credentials based solely on unsolicited calls or messages.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in