IT Help Desk Impersonation Lets Hackers Bypass MFA
Attackers call companies posing as IT help desks, trick executives into visiting fake login pages, and steal their Microsoft 365 accounts, even when multi-factor authentication is enabled. No malware is needed; just a phone call and a fake website.
- Report priority
- High
- Involves
- SaaS environments
What is known
- Attackers call executives pretending to be IT help desks.
- They direct victims to fake login pages that look like Microsoft 365's real sign-in.
- When victims enter their credentials and approve multi-factor codes, the attackers capture them in real time.
- Then they replay those stolen sessions from fake IP addresses that match the victim's real location, letting them access the account as if they were the victim.
What to do
If you're an executive, director, or VP who recently got a phone call from someone claiming to be IT help desk support, check your Microsoft 365 account for unusual sign-in activity, especially from unfamiliar locations or devices. If you see logins you didn't make, immediately reset your Microsoft 365 password and enable Conditional Access in your admin portal to block sign-ins from unknown locations.
Report the call to your IT team and ask them to review your account for unauthorized access. Microsoft also offers a Security Health Check tool to detect suspicious activity.
Reported details
An attacker calls a company's VP of Operations, claiming to be from the IT help desk. The attacker says the VP's account needs verification and gives a fake Microsoft 365 login link. When the VP enters their password and approves the multi-factor code, the attacker captures it. Later, the attacker uses a residential proxy to log in from the VP's city, stealing emails, files, and other data before demanding a ransom.
A social engineering campaign, tracked as PREY-0058, exploits Microsoft 365 and SaaS environments by impersonating internal IT help desk staff via phone calls. Attackers direct executives to fake authentication portals, intercepting credentials and multi-factor approvals in real time. Stolen session tokens are replayed from residential proxies matching the victim's geographic location, bypassing impossible travel alerts.
Once access is gained, threat actors harvest data from SharePoint, OneDrive, Exchange, and Box by querying metadata and draining sensitive files before demanding extortion. The campaign targets high-value accounts, particularly executives, and evades detection by mimicking legitimate sign-in activity. No software vulnerabilities or exploits are involved, only phishing and credential theft.