Executive-Targeted Microsoft 365 Extortion Campaign Leverages IT Help Desk Vishing and AitM Token Theft
Threat actors conduct vishing calls, intercept session tokens via adversary-in-the-middle proxies, and use residential IP sign-ins to bypass MFA and exfiltrate sensitive data.

Key Takeaways
- A coordinated campaign targets Microsoft 365 executive accounts using a multi-stage attack chain.
- The attack begins with vishing calls to IT help desks to socially engineer MFA enrollment or password resets.
- Adversary-in-the-middle (AitM) proxies are used to intercept session tokens and hijack active sessions.
Related Security News

ShinyHunters Claims FBI Breach via Oracle PeopleSoft Zero-Day
The ShinyHunters ransomware operation claims it breached FBI systems using a previously unknown Oracle PeopleSoft vulnerability, exfiltrating sensitive employee and applicant data. As of now, neither the FBI nor Oracle has confirmed the breach or the existence of a zero-day CVE.

Citrix NetScaler Zero-Days Exploited in the Wild; Agencies Urge Immediate Restriction
Cybersecurity agencies, security researchers, and IT providers are warning that two zero-day vulnerabilities in Citrix NetScaler products are being actively exploited in the wild. Exploitation was reported in late September 2026, with private and public advisories issued ahead of patches expected to be released next week. Organizations using unpatched NetScaler appliances face risks of unauthorized access, data exfiltration, and service disruption. Until patches are applied, administrators are advised to shut down or restrict NetScaler appliances.



