Microsoft tracked attackers who phoned staff to breach 365 accounts.
BleepingComputer reported on 11 September 2026 on Microsoft research into a campaign running since May.
Callers pose as the IT help desk and tell employees they must update a passkey, MFA or SSO setting now.
A link then arrives by SMS, often on the employee's personal phone, and opens a page that looks like a Microsoft sign-in. Some victims enter their credentials into an adversary-in-the-middle site, which intercepts the session token. Others approve a device-code request for an application the attacker controls.
Microsoft said: "The actor appears to invest heavily in pre-attack research, likely gathering information about employees and organizational structure from public sources."
Microsoft tracks the activity as Storm-3121 and Storm-3032; Google Threat Intelligence links related activity to UNC6671.
The callers use the words your own security programme has been teaching all year: passkey, MFA, SSO.
Who is authorised to phone your staff and ask them to change an authentication setting?
Sources
Our file on Microsoft
- 20 Sept
Infor shipped three AI agents into a distributor's ERP in two weeks.
- 19 Sept
Microsoft's AI agents rewrote 430,000 lines of Copilot code. The tokens cost $120,000.
- 17 Sept
Microsoft confirmed an Excel security update can silently break paste. No fix date yet.
- 17 Sept
Broadcom raised VMware prices by 10x or more, European cloud providers say.
- 15 Sept
Microsoft knocked out Remote Desktop with two September security updates.
For your next steering committee
- 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
- 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
- 3Ask how long a restore took the last time it was tested.
Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01
Welcome back. · Issue 01
