A New Twist on an Old Trick: Vishing Meets Automation

A threat group tracked as UNC6671 has found a way to combine an old-school social engineering tactic with modern automation, and the results are proving costly for the organizations caught in its path. According to reporting on the group's activity, UNC6671 impersonates internal IT helpdesk staff over the phone to trick employees into handing over access to their Microsoft 365 and Okta accounts. Once inside, the group steals active session tokens, effectively letting attackers bypass passwords and multi-factor authentication entirely, then automates the theft of corporate data for extortion purposes.

What makes this campaign notable isn't the initial contact method. Voice phishing, or "vishing," has been a known tactic for years. It's the automation layered on top that turns a single successful phone call into a scalable data theft operation, one that can quietly harvest files and communications across an entire Microsoft 365 environment before anyone notices.

How the Attack Actually Works

The attack typically begins with a phone call. An employee receives what appears to be a routine call from their company's IT support team, often referencing a plausible technical issue like a login problem or account lockout. The caller guides the target through steps that ultimately hand over an active session token or credentials tied to Microsoft 365 or Okta, the identity platform many organizations use to manage single sign-on access across their cloud tools.

Session tokens are particularly valuable to attackers because they represent an already-authenticated session. Rather than needing to crack a password or defeat multi-factor authentication, the attacker simply reuses the token to impersonate the legitimate user, often without triggering the alerts that a new, suspicious login might generate.

Once that access is established, UNC6671 has reportedly automated the process of pulling data out of the compromised Microsoft 365 environment. Instead of a human operator manually digging through mailboxes and shared drives, scripted tools do the heavy lifting, collecting emails, files, and other sensitive material at scale. That stolen data then becomes leverage in an extortion scheme, with the group threatening to leak or sell the information unless payment is made.

This pattern echoes what researchers have documented in attacks against hedge funds tied to the same extortion group, where financial firms were targeted using similar social engineering and data extortion tactics. Financial services organizations tend to be attractive targets because they hold large volumes of sensitive client data and often face pressure to resolve incidents quickly and quietly.

Why This Matters Beyond the Breach Headlines

It's tempting to treat this as another corporate breach story, but the privacy implications ripple outward. When a threat group hijacks an employee's Microsoft 365 session, they're not just accessing internal company files. They potentially gain visibility into client records, personal data belonging to customers or partners, and internal communications that were never meant to leave the organization.

Because the initial access relies on social engineering rather than a technical exploit, traditional security tools like patching or endpoint detection don't stop the attack at the source. The vulnerability being exploited is human trust, specifically, an employee's reasonable assumption that a call claiming to be from IT support actually is from IT support. That makes this style of attack difficult to fully eliminate through technology alone, and it puts more weight on organizational training and verification processes.

The automation angle also matters. Once a session token is stolen, the speed and scale at which data can be exfiltrated leaves a shrinking window for security teams to detect and respond before significant amounts of sensitive information are already gone.

What This Means For You

If you work at an organization that uses Microsoft 365 or Okta, and most large employers do, this campaign is a reminder that your own vigilance during a routine-seeming IT call matters more than it might seem. Legitimate IT departments rarely ask employees to read out one-time codes, approve unexpected login prompts, or navigate to unfamiliar reset pages during an unsolicited call.

For individuals, the takeaway is less about downloading new software and more about habits. Be skeptical of unsolicited calls asking for account access, even if the caller sounds knowledgeable about your company's internal systems. Verify requests through a separate, known channel, such as calling your IT department back using a number from an internal directory rather than one provided by the caller.

Actionable Takeaways

A few practical steps can reduce your exposure to this type of attack:

  • Treat unsolicited IT support calls with caution, especially ones requesting login codes, session approvals, or password resets.
  • Verify any IT request through an independently sourced phone number or internal chat system, not a callback number given during the suspicious call.
  • Report unusual helpdesk calls to your security team immediately, even if you didn't share any information, since it may indicate your organization is being targeted.
  • If you suspect your session was compromised, ask IT to revoke active tokens and force a fresh login with multi-factor authentication.

UNC6671's campaign shows that as organizations harden their technical defenses, attackers increasingly target the human layer instead. Staying alert to social engineering attempts remains one of the most effective, low-cost defenses available to everyday employees.