Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Microsoft tracked attackers who phoned staff to breach 365 accounts.

BleepingComputer reported on 11 September 2026 on Microsoft research into a campaign running since May.

ERP LEADERS news desk · · First reported by BleepingComputer · Edition no. 6

Callers pose as the IT help desk and tell employees they must update a passkey, MFA or SSO setting now.

A link then arrives by SMS, often on the employee's personal phone, and opens a page that looks like a Microsoft sign-in. Some victims enter their credentials into an adversary-in-the-middle site, which intercepts the session token. Others approve a device-code request for an application the attacker controls.

Microsoft said: "The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources."

Microsoft tracks the activity as Storm-3121 and Storm-3032; Google Threat Intelligence links related activity to UNC6671.

The callers use the words your own security programme has been teaching all year: passkey, MFA, SSO.

Who is authorised to phone your staff and ask them to change an authentication setting?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on Microsoft

  1. 20 SeptFiled later

    Infor shipped three AI agents into a distributor's ERP in two weeks.

  2. 19 SeptFiled later

    Microsoft's AI agents rewrote 430,000 lines of Copilot code. The tokens cost $120,000.

  3. 17 SeptFiled later

    Microsoft confirmed an Excel security update can silently break paste. No fix date yet.

  4. 17 SeptFiled later

    Broadcom raised VMware prices by 10x or more, European cloud providers say.

  5. 15 SeptFiled later

    Microsoft knocked out Remote Desktop with two September security updates.

All 15 Microsoft stories

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01