Executive Summary
Arctic Wolf identified PREY-0058, a widespread data theft and extortion campaign targeting Microsoft 365 and SaaS platforms through sophisticated vishing attacks. The threat actors impersonate IT help desk personnel, directing executives to fraudulent authentication pages that harvest credentials and MFA tokens via adversary-in-the-middle techniques. Using residential proxy infrastructure like NodeMaven, attackers perform session replay attacks to access SharePoint, OneDrive, Exchange, and Box for mass data exfiltration before issuing extortion demands. The campaign primarily targets directors and executives across construction, healthcare, finance, and professional services sectors.
This incident highlights the growing sophistication of identity-based attacks that bypass traditional security controls. As organizations increasingly rely on cloud services and remote access, vishing campaigns exploiting human factors and legitimate authentication flows represent a critical threat vector requiring enhanced user education and phishing-resistant authentication measures.
Why This Matters Now
The PREY-0058 campaign demonstrates how threat actors are evolving beyond malware to exploit human psychology and cloud authentication systems, making traditional endpoint security insufficient against modern identity-focused attacks targeting executive leadership.
Attack Path Analysis
PREY-0058 conducts vishing attacks impersonating IT help desk to direct executives to fake authentication portals, harvesting credentials and MFA tokens through adversary-in-the-middle techniques. Using stolen session tokens, attackers perform reconnaissance against SharePoint and Entra ID, then conduct mass data exfiltration from Microsoft 365 services before sending extortion demands.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors conduct vishing attacks impersonating internal IT help desk personnel, directing targets to authentication-themed domains that host adversary-in-the-middle Microsoft 365 login flows to harvest credentials and MFA approvals
MITRE ATT&CK® Techniques
Phishing: Spear Phishing Voice
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Valid Accounts: Cloud Accounts
Steal Web Session Cookie
Account Discovery: Cloud Account
Data from Information Repositories: SharePoint
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Obtain Capabilities: Code Signing Certificates
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Identity and Access Management - Authentication
Control ID: ID.AM-2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Multi-factor Authentication for All Access
Control ID: 8.4.2
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Executive targeting through vishing and Microsoft 365 token theft creates severe data exfiltration risks requiring enhanced conditional access policies and phishing-resistant MFA.
Health Care / Life Sciences
Healthcare executives face HIPAA compliance violations from SharePoint and Exchange data theft, necessitating zero trust segmentation and encrypted traffic controls.
Construction
Construction sector specifically targeted by PREY-0058 operators using residential proxy infrastructure to bypass geographic restrictions and steal sensitive project data.
Real Estate/Mortgage
Real estate management firms targeted for bulk data collection from OneDrive and Box platforms, requiring egress security policies and anomaly detection.
Sources
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attackshttps://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.htmlVerified
- Arctic Wolf PREY-0058 Threat Intelligence Reporthttps://github.com/rtkwlf/wolf-tools/tree/main/pack_alerts/202609-cloud-data-theft-extortion-vishing-proxiesVerified
- UNC6671 Vishing Attacks Target Personal Informationhttps://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.htmlVerified
- Microsoft 365 Security Best Practiceshttps://docs.microsoft.com/en-us/microsoft-365/security/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this Microsoft 365 compromise by limiting lateral movement and reducing the blast radius of authenticated session abuse through workload segmentation and controlled egress enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust network controls would likely limit unauthorized session establishment and reduce the scope of initial authenticated access to Microsoft 365 services through identity-aware routing policies
Control: Zero Trust Segmentation
Mitigation: Segmentation policies would likely constrain session replay effectiveness by limiting cross-service access and reducing the privilege scope available to replayed authentication tokens across Microsoft 365 workloads
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely restrict cross-application enumeration and limit the attacker's ability to discover available services and expand access across the Microsoft 365 tenant environment
Control: Multicloud Visibility & Control
Mitigation: Visibility and control mechanisms would likely detect and constrain systematic enumeration activities across SharePoint and Entra ID, reducing the scope of data discovery through monitoring and policy enforcement
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain mass data extraction by limiting outbound data flows and reducing the volume of information that could be transferred from Microsoft 365 services through policy-based restrictions
While extortion demands would likely still occur, the constrained data access and reduced exfiltration scope from prior CNSF controls would limit the volume and sensitivity of compromised information available for leverage
Impact at a Glance
Affected Business Functions
- Email Communication Systems
- Document Management and Collaboration
- Executive Decision Making
- Confidential Business Operations
Estimated downtime: N/A
Estimated loss: N/A
Comprehensive data theft from Microsoft 365 environments including SharePoint documents, OneDrive files, Exchange emails, and Box storage. Primary targets are executives and senior staff across construction, healthcare, pharmaceuticals, real estate, finance, and professional services sectors. Stolen data is used for extortion demands.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation with identity-based policies to limit SharePoint and Exchange access scope, preventing mass data enumeration even with compromised credentials
- • Implement Egress Security & Policy Enforcement to detect and block bulk data transfers from Microsoft 365 services to unauthorized external destinations
- • Enable Multicloud Visibility & Control to identify anomalous residential proxy authentication patterns and repeated bulk access to cloud resources
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on suspicious bulk SharePoint discovery and mailbox harvesting activities
- • Strengthen Encrypted Traffic controls and session monitoring to detect token replay attacks and enforce geographic and behavioral authentication policies



