Crypto Ticker:
sysadmin from Cyber Security News

UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

Tushar Subhra Dutta
6 hours ago
7 Views
0 Comments
UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

UNC6671 is carrying out data theft campaigns that begin with a phone call. The group poses as an IT helpdesk, claiming an urgent security migration is necessary. A convincing call and a fake sign-in page can turn an ordinary session into an entry point. The calls create urgency before employees can verify the request independently. The campaign is dangerous because it does not need to crack a password. It captures credentials and a live authentication token. That token lets an intruder act as the employee in Microsoft 365 or Okta, to access mail, files and other stored corporate data. Analysts at Google Cloud identified the activity during ongoing data theft and extortion. Google Cloud said in a report shared with Cyber...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!