Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Fake IT support calls and advanced phishing kits are targeting enterprise executives in coordinated Microsoft 365 data theft campaigns.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reports across the technology sector highlight a wave of sophisticated cyber attacks targeting corporate leadership. According to coverage from outlets including The Hacker News, fake IT support calls are actively targeting executives in an effort to execute Microsoft 365 data theft and extortion operations. Meanwhile, IT Security Guru documented the emergence of a new phishing kit known as Knight Office, which captures credentials without requiring traditional password inputs. Furthermore, research published by CloudSEK outlines ongoing technical tracking efforts focused on the BigBear 2.0 campaign, which utilizes Evilginx2 infrastructure to compromise enterprise defenses. Media coverage places heavy emphasis on the operational methods used by these threat actors to bypass standard security protocols.
Outlets such as BleepingComputer, The Hacker News, CloudSEK, and IT Security Guru have all published distinct analyses focusing on the mechanics of these campaigns. The reports detail how attackers combine human-targeted social engineering via telephone calls with automated infrastructure like Evilginx2 and specialized kits. Coverage does not yet specify the full list of impacted entities beyond the organization count provided by BleepingComputer, nor does it identify specific individuals targeted by the phone calls. This trend emerges against a backdrop of escalating threats against cloud productivity suites used by global enterprises. Microsoft 365 environments remain primary targets for malicious actors seeking unauthorized access to sensitive corporate data, intellectual property, and communication channels.
The utilization of advanced techniques such as multi-factor authentication bypassing and session hijacking reflects a broader shift away from brute-force password attacks toward adversary-in-the-middle strategies. Security researchers tracking tools like Knight Office and BigBear 2.0 note that these kits are specifically designed to subvert modern security baselines that rely solely on standard multi-factor authentication prompts. Observers and security teams are monitoring the situation to see how vendors and affected entities respond to the BigBear and Knight Office threats. Coverage does not currently specify immediate remediation timelines, law enforcement involvement, or official patches from Microsoft regarding the specific attack vectors described. Future updates from reporting outlets and threat intelligence firms like CloudSEK are expected to provide further technical indicators of compromise and additional mitigation strategies for enterprise defenders attempting to secure their executive personnel against telephone-based social engineering and advanced phishing frameworks.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (94% supported) Updated 3h ago.
Quick answers
What is the BigBear campaign?
Coverage from BleepingComputer and CloudSEK identifies BigBear and BigBear 2.0 as a phishing service and campaign utilizing Evilginx2 to bypass multi-factor authentication.
What does the Knight Office kit do?
According to IT Security Guru, the Knight Office phishing kit steals Microsoft 365 logins without touching a password.
Who is being targeted by these attacks?
The Hacker News reports that fake IT calls are specifically targeting corporate executives in Microsoft 365 data theft and extortion attacks.
Coverage (6)
- IT Help Desk Impersonation Lets Hackers Bypass MFA Security Affairs · 18h ago
- BigBear 2.0 Phishing Campaign Steals 5,000 Microsoft 365 Credentials After Bypassing MFA Windows Report · 18h ago
- New ‘Knight Office’ Phishing Kit Steals Microsoft 365 Logins Without Touching a Password IT Security Guru · 18h ago
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations BleepingComputer · 18h ago
- Tracking BigBear 2.0 Evilginx2 Phishing Campaign CloudSEK · 18h ago
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks The Hacker News · 18h ago
Topics
Related trends
Microsoft (MSFT)’s Outlook and OpenAI’s ChatGPT Work Both Broke the Same Day
A simultaneous failure of Microsoft Outlook and OpenAI's ChatGPT has disrupted global digital workflows on September 7, 2026.
Microsoft says KB5120998 Windows update resets desktop settings
Microsoft confirms the KB5120998 Windows update resets desktop settings, according to recent technology reporting.
Massive Microsoft 365 outage causes auth issues, service failures
Android Authority coverage examines a widespread service failure impacting Microsoft Outlook, OneDrive, and other Microsoft 365 tools.
OpenAI confirms ChatGPT outage as users report errors
2 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Microsoft 365 outage drags on, but things are improving
6 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.
Microsoft Outlook Outage Appears Mostly Resolved
1 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.