Fake IT calls turn executive Microsoft 365 sessions into extortion
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 9th, 2026.
Executives are losing cloud data without malware after callers posing as internal IT capture Microsoft 365 sessions. The attackers guide targets to company-themed login pages that relay passwords and multifactor approvals in real time. They then steal the authenticated session token. Using residential proxies, the attackers open account pages, map SharePoint and connected applications, and collect data from SharePoint, OneDrive, Exchange, Box, and other services. The activity has ended in data theft and extortion.
Directors and vice presidents are frequent targets because their accounts often provide access to valuable business information. Residential proxies matched to a victim’s location can also weaken basic impossible-travel alerts. Leaders should require employees to verify unexpected support calls through a trusted internal channel before taking any action. Defenders should deploy phishing-resistant authentication, require managed devices, reduce broad SharePoint access, and watch for token replay, mailbox harvesting, and bulk file activity. The broader lesson is that authenticated cloud sessions have become a primary extortion route. Require trusted-channel verification for IT calls and revoke sessions immediately when token theft is suspected.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.news.