Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat actors use Microsoft 365's own security features to impersonate legitimate IT support and steal sensitive information from executives.

Bottom line: Microsoft 365 users are at risk of data theft and extortion due to sophisticated phishing attacks.

What's happening: Cybersecurity threat actors, reportedly linked to the APT10 group, have been targeting executives through Microsoft 365 help desk vishing attacks, using the platform's own security features to impersonate legitimate IT support.

What to do: Security leaders should ensure that all Microsoft 365 users are aware of the risks and take steps to implement multi-factor authentication and regular security audits to prevent unauthorized access.

Source: The Hacker News