CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

September 7, 2026

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks Ravie LakshmananSep 07, 2026Phishing / Identity Security Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671. It also said that the data extortion threat actor known as Cinder likely represents yet another rebrand or a possible continuation of Pink operations,…