Wednesday Wisdom: The Fake IT Call : Why Your Most Privileged People Are the New Front Door

Confident executive standing in a naturally lit modern office, representing leadership responsibility in cybersecurity

A phone call from “internal IT” can now open the door to your Microsoft 365 environment.

The caller may sound professional. The request may seem routine. They may say they are helping you register a passkey, resolve an MFA issue, or complete a security update. They may stay with you while you sign in.

That is the danger.

The attack does not depend on malware, a technical exploit, or an obviously suspicious email. It depends on trust. More specifically, it depends on the trust executives place in internal support functions and the authority employees associate with a familiar voice.

Recent reporting on the Arctic Wolf-tracked PREY-0058 campaign shows why this deserves executive attention. The campaign targets Directors, Vice Presidents, and other senior employees because their accounts often provide broad access to sensitive data across Microsoft 365 and connected SaaS platforms.

The business lesson is direct. Your most privileged people are now one of your most important security boundaries.

Executives are targeted because their accounts connect valuable data, not because attackers are curious about leadership

The problem is often framed incorrectly. Organizations ask why an attacker would target a busy executive who may not manage technical systems.

The answer is access.

An executive account may provide visibility into board materials, financial information, investor communications, client records, legal documents, acquisition plans, employee data, and strategic correspondence. Through Microsoft 365, that same identity may also reach SharePoint, OneDrive, Exchange, Teams, Box, and other applications connected through single sign-on.

For family offices and high-net-worth individuals, the exposure may include private financial structures and personal records. For RIAs and venture capital firms, it may include client data, investment documents, and transaction communications. For law firms, medical groups, hospitality organizations, and professional services firms, the account may connect to regulated information and high-value relationships.

The fix is to treat executive identity as an enterprise access point, not simply as an individual user account.

Leadership teams should know which systems each executive can reach, which data repositories are available through that identity, and which permissions are necessary for the person’s role. The question is not whether an executive is technically sophisticated. The question is how much operational and reputational exposure is concentrated in that account.

The fake IT call succeeds because trusted process can override security judgment

PREY-0058 begins with vishing. The attacker impersonates internal IT or help desk personnel and guides the target through what sounds like a normal passkey or MFA setup.

The caller may direct the employee to an authentication-themed website. Reported lure domains have included names such as mfaregister[.]com, nowsso[.]com, passkey-mfa[.]com, and setpasskey[.]com. The page is designed to look connected to the victim’s own company.

Behind the page is an adversary-in-the-middle login flow. The employee may enter real credentials and complete real MFA. The attacker captures the resulting authenticated session token and reuses it.

This is why “I completed MFA” is no longer enough to establish that the session was safe.

Our earlier discussion of the MFA illusion focused on session theft and the limits of traditional MFA. This campaign adds the human dimension. A trusted voice can persuade a user to enter the authentication flow in the first place.

The fix is to create a verification culture that applies to executives, partners, and IT staff without exception.

Internal IT should not cold-call users to register passkeys, change authentication methods, or approve unexpected authentication activity without a defined and verifiable process. Employees should be trained to end the call and contact IT through a known internal number, service portal, or established communication channel.

That is not an inconvenience. It is a control.

Business advisor leading a focused cybersecurity discussion with a client team in a modern office

Help desk verification must become a leadership control, not an informal courtesy

Many organizations invest in security awareness training for general employees but leave help desk procedures informal.

That creates a gap.

A caller who impersonates IT does not need to defeat every security control. They only need to convince one trusted person to complete a sensitive action. If the help desk routinely accepts verbal requests, performs MFA resets without independent verification, or guides users through authentication changes during unsolicited calls, the process itself becomes an attack surface.

The fix is a formal help desk verification protocol with executive-level support.

That protocol should include:

  • A requirement for out-of-band verification before password resets, MFA changes, passkey registration, or device enrollment.
  • A prohibition on requesting MFA codes, approval prompts, or passwords from users.
  • A requirement that support staff use approved ticketing and identity-verification workflows.
  • A known callback process using trusted internal contact information.
  • A clear escalation path for unusual executive requests.
  • A simple reporting mechanism for suspicious calls that does not penalize employees for stopping work to verify.

The cultural message matters. Employees should not feel they are challenging leadership or slowing down the business when they verify an IT request. They should understand that verification is part of professional conduct.

This is especially important for organizations where executive assistants, finance leaders, operations directors, and outside advisors frequently act on behalf of senior stakeholders.

Traditional MFA is not the finish line when the authentication flow can be intercepted

The BigBear 2.0 reporting reinforces the same strategic issue. CloudSEK identified a phishing-as-a-service operation associated with approximately 5,137 credential records, including 474 complete MFA-bypassed authentications and 4,148 session cookies across hundreds of organizations.

The service used an Evilginx2-based adversary-in-the-middle framework. Reporting also found that custom JavaScript interfered with FIDO2 and WebAuthn options, pushing victims toward weaker authentication methods that could be intercepted.

The point is not that MFA has failed. MFA remains important. The point is that different MFA methods provide different levels of resistance to modern identity attacks.

The fix is to prioritize phishing-resistant MFA for executives, administrators, finance personnel, and other high-impact users.

FIDO2 security keys and device-bound passkeys bind authentication to the legitimate service origin. They are designed to prevent an attacker-controlled intermediary from successfully relaying the authentication event.

That control should be paired with Conditional Access policies that require managed or compliant devices, challenge or block proxy and hosting-provider traffic, and consider sign-in risk rather than relying only on geographic location. Residential proxy services can make attacker activity appear to originate near the victim and from a familiar network type.

Identity controls must evaluate the quality of the session, not merely whether a user completed a prompt.

Professionals collaborating around a conference table in a modern office, representing coordinated access and security oversight

Data segmentation limits the damage when one privileged session is compromised

After access is established, PREY-0058 operators reportedly perform discovery across SharePoint and Entra ID. They then collect data from SharePoint, OneDrive, Exchange, and Box.

Notably, the activity has not required endpoint malware or traditional network-based lateral movement. The attackers can use legitimate cloud access and authenticated sessions to search, read, and download information.

That changes the leadership question. It is not enough to ask whether an attacker can enter. We must also ask what a single compromised identity can reach once inside.

The fix is to reduce the amount of sensitive data available through any one account.

Organizations should review SharePoint and OneDrive permissions by role, remove broad “all company” access where it is not necessary, segment highly sensitive data into restricted sites, and apply additional safeguards to legal, financial, client, health, and transaction records.

Monitoring should also focus on behavior that indicates collection:

  • Unusual sign-ins from residential proxy or hosting infrastructure.
  • New sessions that differ from the user’s normal device, browser, or network profile.
  • Rapid SharePoint discovery across multiple sites.
  • Large volumes of FileAccessed or FileDownloaded activity.
  • Unusual MailItemsAccessed activity in a short period.
  • New authentication-themed domains containing the organization’s name.
  • Sudden access to applications the user rarely uses.

These signals should reach someone who can make a business decision quickly. A security alert that no leader reviews is not a control.

Executive oversight turns identity security into revenue protection

A compromised executive account can create more than a technical incident. It can expose client information, trigger regulatory obligations, interrupt operations, enable fraud, and damage leadership credibility.

For regulated and relationship-driven organizations, the growth reputation may be as important as the immediate cost. Clients want to know that their information is protected by disciplined processes, not by individual caution alone.

The fix is regular executive reporting on identity risk.

Leadership should receive clear answers to several questions:

  • Which privileged accounts use phishing-resistant MFA?
  • Which executive identities have broad access to sensitive repositories?
  • Are help desk verification procedures tested?
  • How quickly can active sessions and refresh tokens be revoked?
  • Are anomalous sign-ins and bulk downloads monitored?
  • Has the organization rehearsed a response to a compromised executive account?
  • Which risks remain open, and who owns the decision to address them?

We do not need more fear-driven security messaging. We need accountability, visibility, and practical decisions.

At [Oram Cybersecurity Advisors](https://www.oramca.com/security), we help growth-minded organizations connect Microsoft 365 security, managed IT operations, compliance responsibilities, and business priorities. Technology should support the strategy of the organization, not quietly create operational risk behind it.

A fake IT call is not merely an employee awareness problem. It is a leadership, access, and governance problem.

The fix is a practical conversation about who can access what, how that access is verified, and how quickly your organization can respond when trust is misused. [Contact Oram Cybersecurity Advisors](https://www.oramca.com/contact-us) to bring clarity to your identity and employee access security strategy.

Sources

  • [The Hacker News: Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks](https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html), September 7, 2026.
  • [Help Net Security: IT help-desk vishing tricks executives into handing over Microsoft 365 access](https://www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/), September 8, 2026.
  • [BleepingComputer: BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/), September 7, 2026.
  • [CloudSEK: Tracking BigBear 2.0 Evilginx2 Phishing Campaign](https://www.cloudsek.com/ar/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign), September 7, 2026.
  • [Arctic Wolf GitHub indicators of compromise for the 2026 cloud data theft and extortion vishing cluster](https://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxies).
Oram Cybersecurity Advisors logo
Previous
Previous

Scam of the Week: The Reply Trap

Next
Next

Scam of the Week: This Text Is a Trick