# Vishing campaign targets executives for Microsoft 365 data theft

_Monday, September 7, 2026 at 11:51 AM EDT · Security · Latest · Tier 2 — Notable_

![Vishing campaign targets executives for Microsoft 365 data theft — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg-Zo4zgxCrVcz6-00WV2qAPHSD-av2Ed5hgRmR-2vUzkr9jVeph0NNb6gGsQfwSkFyuRfRcSsaISSpfysl_Xx5F48IM7HdBpO4F3CaVuLhk1v0a4vcH5xK_bxX6BxIjkfAjhDaNGcLG7_R9IcTjVGlFcW7y1ZV64imACHi9528LOjH1Flhk-cy9LFgrMv/s1700-nu-rw-lo-l85-e365/phish-ms.jpg)

Arctic Wolf has described a data-theft and extortion cluster targeting Microsoft 365 and other SaaS accounts through fraudulent IT-help-desk calls, adversary-in-the-middle login pages and residential-proxy session replay. The activity, tracked as PREY-0058, primarily targets executives and proceeds to SharePoint, Entra ID, OneDrive, Exchange and Box discovery before bulk collection and extortion. Arctic Wolf said the lure infrastructure includes hundreds of subdomains impersonating real companies.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html)

---
Canonical: https://techandbusiness.org/newswire/wS2QjmwMPwOsECaRQ7bM1w
Retrieved: 2026-09-08T07:56:32.179Z
Publisher: Tech & Business (techandbusiness.org)
