Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS Platforms

Published September 10, 2026

A criminal group is calling companies pretending to be IT support, tricking executives into giving up their login details. Once inside, they steal sensitive files from Microsoft 365 and other cloud services, then demand money to keep the data private.

Report priority
High
Victim
Threat actor: PREY-0058

What is known

  • Attackers call or text executives pretending to be IT helpdesk staff.
  • They trick victims into visiting fake login pages that steal passwords, even when multi-factor authentication is enabled.
  • Once inside, the attackers use automated tools to quickly copy emails, documents, and cloud files without locking systems.
  • They then send threats via encrypted messaging, demanding payment to avoid leaking the stolen data.

What to do

If you work for a finance or tech company and recently got a call or text from an unknown IT support number asking to verify your login details, check if your company has issued a security alert. Look for unusual login attempts in your Microsoft 365 or cloud account activity logs. If you see logins from unknown locations or devices, contact your company's IT security team immediately if you suspect your account was accessed without permission.

Change your password and enable additional security checks like a hardware key or app-based code. Ask your IT team if they've seen signs of this campaign in your company's systems. If your company has been targeted, follow their instructions for reporting suspicious activity or recovering accounts.

Reported details

A finance company's CFO received a text from a fake IT support number asking to verify credentials. The link led to a cloned Microsoft login page that stole their password. Attackers then copied all emails and files from Microsoft 365 and demanded $250,000 to delete them.

A targeted data theft and extortion campaign (tracked as PREY-0058) leverages IT impersonation and voice-phishing to trick executives and senior personnel into handing over credentials via fake helpdesk portals. Attackers bypass multi-factor authentication (MFA) and rapidly exfiltrate sensitive data from Microsoft 365 and SaaS platforms, including email, file storage, and cloud repositories, without deploying ransomware. The operation uses NodeMaven residential proxies to mask malicious activity within legitimate traffic.

Extortion demands are delivered via TOX messaging within hours of compromise, often with 72-hour deadlines and threats of public data exposure. The campaign shares tradecraft with UNC6671 and involves multiple extortionware brands, including BlackFile, Redact, Pink, and Helix. The OTX-6aa2affe4ab7ba9012836da5 identifier tracks this activity.