Microsoft 365 Accounts Under Attack Via Social Engineering Tactics
Attackers are using social engineering tactics to break into Microsoft 365 accounts by calling employees on their personal phones, posing as internal IT staff. According to Microsoft Security Research, this campaign has been ongoing since May 2026 and involves tricking employees into handing over access to corporate cloud accounts.
The attackers create a sense of urgency by explaining that a passkey or multifactor authentication configuration must be updated immediately to avoid disruption. They then send a link to a page built to look like a Microsoft sign-in screen, where the employee is prompted to enter their credentials.
Researchers found that in several cases, the only lead investigators had was an employee remembering the call or text. The attackers appear to do their homework before making contact, gathering details about staff and organizational structure from public sources, including professional networking sites.
Once inside an account, the attackers register a phone number, authenticator app, or software-based one-time password token of their own under the compromised identity, allowing them to stay in the account even after the initial stolen token or session expires.