Attackers Pose as IT Staff to Compromise Microsoft 365 Accounts
Microsoft 365 account compromises have been linked to attackers posing as IT staff who trick employees into updating their passkeys or other sign-in settings. According to Microsoft Security Research, this tactic has been used since May across multiple accounts.
The attack begins with a call or text to an employee's personal phone, where the disguised IT helpdesk staff warns that access could be lost if they don't update a passkey, multifactor authentication, or single sign-on setting. The attackers then direct employees to pages that look similar to legitimate Microsoft sign-in screens.
Microsoft describes several routes from the request to account access, including instances where an attacker-controlled site relayed a sign-in to Microsoft and captured credentials and a session token after the employee completed an MFA check. In another instance, the employee entered a device code on Microsoft's real authentication page, authorizing an attacker-controlled client to receive a token.
The attackers used Microsoft Graph to examine users, permissions, applications, and available files, with some instances of SharePoint and OneDrive downloads and email access through Exchange.