Threat hunters disclosed a widespread data theft and extortion campaign on September 7 that targets directors, vice presidents, and executive staff at organizations using Microsoft 365 and other SaaS platforms. The attack chain combines IT help desk vishing—voice phishing over phone calls—with adversary-in-the-middle token theft and sign-ins originating from residential proxies to evade detection.
The campaign singles out high-value executive accounts to maximize the impact of data theft and extortion. Attackers gain access to sensitive corporate strategy, decision-maker communications, and privileged accounts that can authorize financial transactions or access confidential systems.
IT Help Desk Vishing Delivers Adversary-in-the-Middle Token Theft Against Executive Accounts
The attack begins with a phone call impersonating the organization’s IT help desk. Attackers use social engineering to convince executives that urgent account security measures are required. The call directs victims to a phishing site that intercepts their Microsoft 365 credentials and MFA responses through an adversary-in-the-middle attack.
When the executive completes authentication—including any required multi-factor challenge—the attacker’s infrastructure captures the resulting session token. This token provides full access to the compromised account without requiring the attacker to possess the victim’s password or second factor. The technique bypasses MFA because the authentication system sees a valid session that completed all required security checks.
Why Attackers Use Residential Proxies to Obscure Executive Account Compromise
Sign-ins from the stolen session tokens originate from residential proxy IP addresses rather than data center or VPN sources. Residential proxies route traffic through legitimate home internet connections, making authentication attempts appear to come from typical consumer ISPs. This technique evades detection rules that flag data center IPs and known VPN exit nodes as suspicious authentication sources.
Security teams commonly implement conditional access policies that block or challenge logins from unusual geographic locations or untrusted networks. Residential proxies complicate this defense by presenting IP addresses that blend with normal remote work patterns. An executive logging in from a residential ISP in a different city might represent legitimate travel or remote work, making it difficult to distinguish from an attacker using a residential proxy in the same region.
The focus on directors, VPs, and executive staff reflects the higher value of these accounts for both data theft and extortion. Executive email contains strategic plans, M&A discussions, confidential HR matters, and customer relationship details that competitors or extortionists can monetize. Executives also hold authority to approve financial transactions, making compromised accounts useful for business email compromise and wire transfer fraud.
Organizations Must Train Executives on Vishing Threats and Enforce Out-of-Band Verification
Executive security training should specifically address vishing threats, including fake IT help desk calls that create urgency around account security. Real IT departments do not initiate unsolicited password resets or MFA re-enrollment through phone calls. Executives should verify any security-related request through a separate communication channel—calling the IT help desk directly at a known number rather than using contact information provided by the caller.
Out-of-band verification adds friction but prevents social engineering attacks that rely on maintaining control of a single communication channel. When an executive receives a call requesting immediate account action, the correct response is to end the call, independently contact IT through established channels, and verify whether the request is legitimate.
Conditional access policies should enforce additional verification steps for executive accounts, including device compliance requirements and impossible-travel detection that flags rapid geographic shifts in authentication attempts. Residential proxy detection remains challenging, but organizations can monitor for authentication patterns that combine rapid location changes with IP addresses not previously associated with the account.
Security teams should specifically monitor executive accounts for authentication anomalies following any reported suspicious phone calls, even when the executive believes they did not provide credentials. The sophistication of adversary-in-the-middle attacks means victims often complete authentication on what appears to be the legitimate Microsoft 365 login page, unaware that their session token was intercepted. Proactive account reviews after vishing attempts can detect compromise before attackers complete data exfiltration.
The campaign’s targeting of Microsoft 365 and SaaS platforms reflects the migration of corporate data and communications to cloud services. Executives who previously worked primarily on-premises with network-perimeter protections now authenticate to cloud platforms from arbitrary locations, making baseline authentication patterns harder to establish and anomalies harder to detect.
