Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft

1 min read
Source: The Hacker News
Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft
Photo: The Hacker News
TL;DR Summary

Threat actors impersonating IT desk staff use vishing and an adversary-in-the-middle token theft flow to harvest Microsoft 365 credentials and MFA approvals, enabling access to authenticated sessions via proxy replay; they exfiltrate data from SharePoint, OneDrive, Exchange, and Box, targeting executives across sectors. Defenses include phishing-resistant MFA, Conditional Access, restricting SharePoint data access, and employee training on vishing risks.

Share this article

Reading Insights

Total Reads

1

Unique Readers

7

Time Saved

2 min

vs 3 min read

Condensed

88%

50259 words

Want the full story? Read the original article

Read on The Hacker News