Vishing Scams Steal Access Tokens to Microsoft 365 Accounts
Arctic Wolf reports a wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts via IT help-desk vishing. Attackers stole session tokens, routed sign-ins through residential proxies, and sent authentication links disguised as company-branded subdomains. Researchers identified hundreds of impersonation entries and multiple extortion brands, focused on US organizations in several sectors and executive staff.