Hackers Pose as IT Support to Sidestep MFA, Hijack Microsoft 365 Sessions
Cyber‑criminals are exploiting a social‑engineering technique that allows them to bypass multi‑factor authentication (MFA) by impersonating internal IT help‑desk staff. The approach, observed in a growing threat cluster, enables attackers to seize active Microsoft 365 sessions, siphon data from cloud‑based SaaS applications, and then demand ransom without ever deploying traditional malware.
According to the security‑research community, the scheme begins with a phone call or email that appears to originate from a company’s own support team. Victims are instructed to click a link or provide a one‑time passcode, believing they are complying with a legitimate request. Because the interaction mimics a trusted internal process, users often hand over the credentials needed to generate a valid MFA token, granting the intruder unfettered access to the victim’s cloud environment.
Once inside, the attackers leverage the stolen session to enumerate and extract data from a variety of SaaS platforms—ranging from document repositories to customer relationship tools. The exfiltrated information is then used either for direct resale on underground markets or as leverage in extortion attempts, where perpetrators threaten to expose or destroy the compromised data unless a payment is made.
The tactic marks a shift away from classic ransomware that relies on encrypting files with malicious code. Instead, threat actors are focusing on “phone‑first” extortion, where the mere act of contacting the victim and demanding payment can be enough to coerce compliance. Security analysts warn that this method reduces the technical overhead for attackers and can be deployed at scale, as it does not require the development or distribution of sophisticated malware payloads.
Experts recommend a layered response: reinforcing MFA with phishing‑resistant methods such as hardware security keys, conducting regular security awareness training that emphasizes verification of IT requests, and implementing strict monitoring of privileged session activity. Organizations are also urged to adopt zero‑trust principles that treat every access request as potentially hostile, regardless of its apparent source. As the impersonation technique continues to evolve, vigilance and robust identity‑security controls remain the most effective defenses against this emerging form of cyber extortion.
Comments (0)
Be the first to comment.
Join the discussion