Skip to main content

Fake Help Desk Calls Exploit Executive Data Theft and Extortion Campaign

SUBJECT: Active Exortion Campaign STATUS: 7/10 Severity AUDIENCE: Government, Critical Infrastructure, Transportation and Logistics Security Leads

Sep 7, 2026

·

Blog

·

Secure Communications

Threat hunters have disclosed a widespread data theft and extortion campaign, tracked as PREY-0058, that impersonates internal IT help desk staff by phone to steal Microsoft 365 session tokens from directors, vice presidents, and other executive staff, then exfiltrates data from SharePoint, OneDrive, Exchange, and Box for extortion, without ever deploying malware or moving laterally across the network. 

What Happened — and Why It Is Different

Arctic Wolf has disclosed a widespread data theft and extortion cluster it tracks as PREY-0058, which mainly targets directors, vice presidents, and other executive staff across the United States, concentrated in construction and engineering, healthcare and pharmaceuticals, real estate and property management, finance, and professional services.1 Researchers note the group shares significant tradecraft with a data extortion actor Google-owned Mandiant tracks as UNC6671, and that a separate extortion brand called Cinder likely represents a rebrand or continuation of an earlier group known as Pink.1 

The attack starts with a phone call. Operators impersonate internal IT or help desk personnel and direct the target to an authentication-themed URL following a consistent pattern, the victim organization's name paired with a lure domain such as mfaregister[.]com, passkeydeploy[.]com, or setpasskey[.]com1. The page runs an operator-controlled adversary-in-the-middle Microsoft 365 login flow that harvests credentials and MFA approvals to capture live session tokens.1 Those tokens are replayed through proxy infrastructure, including residential proxy services, chosen to match the victim's own geography and network, so the sign-in doesn't look anomalous to Microsoft's own detection.1 

Once inside, the operators start in ordinary Microsoft applications, My Sign-ins, My Profile, My Apps, to map account details and available applications.1 From there they run discovery against SharePoint and Entra ID using standard search activity, then collect and exfiltrate data en masse from SharePoint, OneDrive, Exchange, and Box before sending extortion demands.1 At no point does the campaign deploy endpoint malware or move laterally across the network.1 Researchers have also found hundreds of lure subdomains impersonating real companies, suggesting the infrastructure is built for reuse across many targets rather than a single operation.1 

What They Found — and What It Means 

Finding 
What It Means 
Operational Consequence 
Open Question 
PREY-0058 targets directors, VPs, and executive staff specifically, using a phone call impersonating IT help desk staff to start the compromise. 
This isn't opportunistic phishing sent broadly and hoping someone clicks. It's a deliberate selection of the people most likely to have broad access and the authority to be trusted without question. 
Standard phishing awareness training aimed at spotting suspicious emails does nothing here, since the entry point is a phone call that never touches an inbox. 
How many organizations have a documented process for an executive to verify a help desk caller's identity before following any instruction. 
The campaign never deploys malware and never moves laterally across the network. Everything after initial token theft happens inside legitimate Microsoft applications and normal-looking search activity. 
Endpoint detection and network monitoring have nothing to alert on, because nothing touches the endpoint or the network in a way those tools are built to catch. 
An organization can be fully compromised, and the data already exfiltrated, while every conventional security tool reports a clean environment. 
Whether the organization's detection strategy accounts for identity-only compromise at all, or assumes a real attack eventually leaves an endpoint or network trace. 

Why This Matters 

Old Assumption 
Current Reality 
BlackBerry Response 
Phishing awareness training, teaching people to scrutinize suspicious emails and links, covers the organization's exposure to credential theft. 
PREY-0058's entry point is a phone call impersonating IT help desk staff, a vector email-focused training doesn't address at all. 
BlackBerry® AtHoc® gives an organization a verified, out-of-band channel for legitimate IT and security communications, so executives have a real alternative to trust instead of whatever a caller claims to represent. 
Endpoint detection and network monitoring will catch a serious compromise before it results in mass data loss. 
This campaign deploys no malware and moves through nothing but normal-looking Microsoft 365 activity, leaving those tools with nothing to flag. 
BlackBerry® UEM solution's Conditional Access enforcement ties sign-in to a managed, compliant device, so a replayed session token from residential proxy infrastructure doesn't match a device the organization has authorized. 
A named threat cluster is a fixed adversary, and disrupting it resolves the risk. 
Researchers describe PREY-0058, UNC6671, Cinder, and Pink as overlapping labels for a shared pool of infrastructure and affiliates that persists across rebrands. 
Standing verification habits and device compliance, the kind AtHoc and UEM support by default, hold up against the underlying tradecraft regardless of which name it operates under next. 
Action
What It Means in Practice
IMMEDIATE 
Establish and communicate a verified process for confirming an internal IT or help desk caller's identity before acting on any instruction delivered by phone, especially requests involving MFA, passkeys, or authentication setup. 
IMMEDIATE 
Treat any authentication-themed URL following the pattern of your organization's name plus a generic lure domain as a compromise attempt, and block known lure domains at the network level where possible. 
SHORT-TERM 
Deploy Conditional Access policies that require a managed, compliant device for sign-in, and restrict the scope of data any single user can access in SharePoint and OneDrive by default. 
SHORT-TERM 
Brief executive assistants and executives directly, not just general staff, since this campaign specifically selects directors, vice presidents, and executive staff as its entry point. 
ONGOING 
Monitor for anomalous residential-proxy token replay and bulk SharePoint or OneDrive access patterns, since this is the detection surface that exists for a campaign built to avoid endpoint and network tooling. 

BlackBerry Secure Communications Position

A campaign that deploys no malware and moves laterally through nothing is not a lucky gap in an organization's defenses. It's a deliberate design choice built around the assumption that most security tooling watches the endpoint and the network, and nothing else. The entry point here is a phone call and a login page, and the only real defense is verifying who's asking before anyone hands over an approval. That must be a standing habit, not a one-time training module, because the people this campaign targets are exactly the ones trained to respond quickly when someone claiming authority calls. 

Citations:

1. Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks (Arctic Wolf, PREY-0058 threat research, as reported by The Hacker News, September 7, 2026). 

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now