Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

**Phantom IT Calls Pose Serious Threat to Executives in Microsoft 365 Data Theft and Extortion Attacks**

In a disturbing trend, cyberattackers have started targeting high-ranking executives with fake IT support calls, compromising their sensitive data and extorting them for ransom. This insidious tactic has been observed in attacks on Microsoft 365 users, where attackers exploit the trust between employees and corporate IT teams to gain access to critical information.

The modus operandi of these attacks is deceptively simple yet effective. Attackers pose as IT support specialists, calling executives on their personal or work phones with urgent messages about supposed security threats or system failures within Microsoft 365. These fake calls often include convincing details such as the executive’s username and other identifiable information, making it difficult for the victim to distinguish reality from fabrication.

Once the attacker gains the trust of the executive, they may request access to their computer to supposedly resolve the issue remotely. However, in reality, this provides the attacker with a backdoor into the corporate network, potentially allowing them to snoop on sensitive data, steal confidential information, or even take control of entire systems. This scenario is particularly concerning given that Microsoft 365 is widely used by businesses for its robust security features and streamlined productivity tools.

The attackers’ ultimate goal in these incidents appears to be financial gain through extortion rather than mere data theft. They may threaten to expose compromising information unless a ransom is paid, leveraging the powerlessness of their victims to extract concessions. This not only puts the targeted executives at risk but also compromises the company’s overall security posture if left unchecked.

The sophistication and precision with which these attacks are carried out underscore the importance for companies to bolster their cybersecurity measures against such social engineering tactics. IT teams must ensure that employees are adequately trained to recognize and report suspicious calls, while also implementing robust verification procedures before granting remote access to any system or network.

**Protect Yourself from Phantom IT Calls**

To mitigate this risk, we recommend that executives and other high-ranking officials exercise extreme caution when receiving unsolicited IT support calls. Verify the caller’s identity through multiple channels, such as checking with the company’s official IT department directly, before allowing them to access your computer or system. Additionally, educate yourself about common phishing tactics and social engineering techniques to better distinguish between genuine support requests and malicious attempts to compromise your security. By being vigilant and proactive in protecting against these threats, you can safeguard not only your personal data but also the integrity of your company’s information systems.


Source: The Hacker News — 2026-09-07