Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Executives Targeted in Microsoft 365 Data Extortion Scam

Executives Targeted in Microsoft 365 Data Extortion Scam

Posted on September 7, 2026 By CWS

Cybersecurity experts have uncovered a significant data theft and extortion operation targeting Microsoft 365 and other software-as-a-service (SaaS) platforms. The campaign, known as PREY-0058, employs tactics such as impersonating IT support via vishing and exploiting adversary-in-the-middle (AitM) token theft. These attacks primarily target senior executives like directors and vice presidents.

Overview of the Threat Campaign

Arctic Wolf, a cybersecurity firm, is monitoring this threat under the codename PREY-0058. The operation shares similarities with another data extortion group tracked by Mandiant, a Google-owned entity, known as UNC6671. Interestingly, the threat actor identified as Cinder appears to be a rebranding or continuation of previous operations associated with the Pink group.

The campaign does not link to a single entity but involves various affiliates or groups using the same phishing infrastructure. This lack of a centralized identity complicates efforts to counteract these threats.

Attack Methods and Techniques

The attack strategy begins with threat actors masquerading as IT help desk personnel, contacting targets by phone and directing them to authentication-themed URLs. Notable domains used in these scams include assignpasskey[.]com and mfaregister[.]com. The goal is to harvest login credentials and multi-factor authentication (MFA) approvals.

Once the credentials are obtained, attackers use the tokens for session replay attacks. These attacks often originate from proxy infrastructure, such as NodeMaven, and occur from IP addresses that match the victim’s location.

Impact and Mitigation Strategies

After gaining access, attackers conduct a discovery process on platforms like SharePoint and Entra ID to gather detailed account information. They perform bulk data collection from SharePoint, OneDrive, Exchange, and Box, followed by extortion demands to the victims.

Despite the absence of endpoint malware or lateral network movements, the threat is significant. The campaign’s infrastructure includes numerous subdomains impersonating legitimate companies, with targets spread across sectors such as construction, healthcare, and finance.

Organizations are advised to adopt Conditional Access policies, enforce phishing-resistant MFA, and restrict data access in SharePoint. Employee education on vishing threats is also crucial. Arctic Wolf suggests monitoring for unusual token replay activity and newly registered lure domains as part of a defensive strategy.

As cyber threats evolve, staying informed and implementing robust security measures remain vital for protecting sensitive data and organizational integrity.

The Hacker News Tags:Arctic Wolf, Cybersecurity, data extortion, identity theft, IT security, Microsoft 365, Phishing, PREY-0058, SaaS threats, token theft, Vishing

Post navigation

Previous Post: Mathspace Data Breach Exposes Over 1 Million Users
Next Post: ScreenConnect Exploited in Cyberattack Campaign

Related Posts

Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure Threat Actors Weaponize HexStrike AI to Exploit Citrix Flaws Within a Week of Disclosure The Hacker News
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active Exploitation CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active Exploitation The Hacker News
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation The Hacker News
Apple Fixes Eavesdropping Flaw in Beats Studio Buds Apple Fixes Eavesdropping Flaw in Beats Studio Buds The Hacker News
Malicious npm Packages Exploit PostCSS Tools for Windows RAT Malicious npm Packages Exploit PostCSS Tools for Windows RAT The Hacker News
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bimbo Bakeries Hit by Oracle EBS Data Breach
  • Critical Security Updates: Chrome 0-Day and More
  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bimbo Bakeries Hit by Oracle EBS Data Breach
  • Critical Security Updates: Chrome 0-Day and More
  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark