Menu
a person wearing a hoodie and a headset

Your helpdesk is calling – or is it?

Posted on 22 September 2026

Reading time 5 minutes

What happened?

Microsoft has identified an active campaign targeting Microsoft 365 cloud accounts, with related activity observed since May 2026. The number and identity of affected organisations and users have not been disclosed.

The campaign uses targeted social engineering rather than exploiting a confirmed vulnerability in Microsoft software. Attackers pose as IT helpdesk staff and contact employees through telephone calls, SMS messages or, in some cases, Microsoft Teams messages sent from compromised accounts. Victims are told that they must urgently update their passkey, multifactor authentication (MFA) or single sign on settings and are directed to convincing imitation sign in pages.

Using adversary in the middle phishing or device code authentication, the attackers obtain credentials, session tokens or access authorised unknowingly by the victim. They then access Microsoft 365, often from unmanaged devices or proxy associated infrastructure, and may register a new phone number, authenticator application or software token as an additional MFA method. This allows them to maintain access beyond the initial compromise.

Once established, the attackers use Microsoft Graph to map the victim’s cloud environment, including its users, groups, roles, applications, permissions, authentication methods and data repositories. They then access and potentially exfiltrate documents from SharePoint and OneDrive, as well as emails and attachments from Exchange Online. Microsoft reports that collection may continue at a controlled pace for several hours or days, helping the activity blend with ordinary business use.

Microsoft detected the campaign by linking unusual sign ins with newly registered authentication methods, extensive Microsoft Graph activity and abnormal access to files and mailboxes. This highlights the importance of assessing cloud activity as a connected sequence, as individual events may appear legitimate in isolation.

Microsoft has linked the techniques to an ecosystem of threat actors that includes Storm 3121 and Storm 3032, whose activity has previously led to ShinyHunters, Falcon and Helix extortion operations. However, Microsoft has not attributed every intrusion in the campaign to a particular group.

So what?

This campaign demonstrates that threat actors do not need to exploit a software vulnerability to compromise a cloud environment. Instead, they are targeting employees’ trust in familiar IT support and authentication processes to obtain legitimate access to Microsoft 365 accounts. Controls such as MFA may provide limited protection where they are not phishing resistant or where users can be persuaded to approve device code authentication or register an attacker-controlled authentication method.

Once an account has been compromised, Microsoft Graph can allow an attacker to map an organisation’s cloud environment and identify valuable users, applications and information. Access to SharePoint, OneDrive and Exchange Online may expose confidential documents, personal data, commercially sensitive emails and attachments. This information could support further fraud, business email compromise or extortion.

The campaign also presents a significant detection challenge. The attackers rotate domains, IP addresses and hosting providers, use legitimate Microsoft authentication processes and collect data gradually over several hours or days. Individual sign ins, Graph requests or file access events may appear legitimate when viewed in isolation. Organisations should therefore focus on the overall behavioural sequence: unusual authentication, the registration of a new MFA method, cloud reconnaissance and subsequent high volume data access.

A successful compromise could lead to financial loss, operational disruption, regulatory scrutiny and reputational damage. Where personal data is affected, organisations will need to assess whether the incident triggers notification obligations under the UK GDPR, including possible notification to the Information Commissioner’s Office and affected individuals. Additional contractual, insurance and sector specific reporting requirements may also apply.

More broadly, the campaign should prompt organisations to reassess the risks arising from cloud identities, unmanaged devices and applications with extensive Microsoft Graph permissions. Organisations that rely on non-phishing resistant MFA, permit unrestricted device code authentication or lack centralised cloud logging may face an increased risk of persistent account compromise and data exfiltration.

What should I do?

Organisations should prioritise identifying potentially compromised Microsoft 365 accounts, containing any unauthorised access and strengthening identity controls. Investigations should connect unusual sign ins with subsequent MFA changes, Microsoft Graph activity and abnormal access to files or mailboxes, rather than treating each event in isolation.

  • Review unusual sign ins and authentication changes: Examine risky sign ins, device code authentication, access from unmanaged devices and anonymous proxies. Check recently added passkeys, telephone numbers, authenticator applications and software tokens, verifying each change directly with the user through a trusted channel.
  • Contain confirmed compromises promptly: Revoke active sessions and refresh tokens, reset credentials, remove unauthorised authentication methods and delete any attacker created mailbox rules. Require affected users to re-register their authentication methods securely.
  • Assess potential data loss: Establish which SharePoint and OneDrive files, emails and attachments were accessed or downloaded. Preserve relevant identity, Microsoft Graph, mailbox and cloud audit logs for forensic, legal and regulatory assessment.
  • Strengthen authentication controls: Enforce phishing resistant MFA, such as FIDO2 security keys, passkeys or Windows Hello for Business. Restrict weaker authentication methods and require fresh, secure authentication before users can register or amend MFA details.
  • Tighten Conditional Access policies: Require managed and compliant devices for access to Exchange, SharePoint and sensitive applications. Block device code and authentication transfer flows unless there is a clear and documented business requirement.
  • Restrict cloud data access: Where practicable, limit unmanaged devices to web only sessions without download or synchronisation. Review external sharing arrangements and disable anonymous SharePoint and OneDrive links unless they are required.
  • Review application permissions: Restrict user consent and require administrator approval for applications where appropriate. Regularly review service principals with extensive Microsoft Graph permissions, including Mail.Read, Files.Read.All and Directory.Read.All.
  • Improve monitoring and detection: Enable Microsoft Graph activity logging and mailbox auditing. Configure alerts for unusual MFA registration, broad tenant reconnaissance, automated access and high volume file or email collection. Indicators such as suspicious domains and IP addresses should support, but not determine, an investigation because attacker infrastructure can change quickly.
  • Train employees and helpdesk teams: Remind staff not to respond to unsolicited calls, texts or Teams messages requesting urgent passkey, MFA or SSO changes. Users should never enter a device code or approve an authentication request initiated by another person. Helpdesk personnel should follow robust identity verification procedures before resetting credentials or MFA.
  • Review reporting obligations: If data may have been compromised, involve legal, data protection and incident response teams promptly to consider notifications to regulators, affected individuals, clients, insurers and other relevant parties.
How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else