Cybercriminals are conducting sophisticated voice phishing campaigns against executives in the financial sector to compromise Microsoft 365 environments. Attackers impersonate internal IT support staff to trick high-level employees into approving authentication requests through adversary-in-the-middle landing pages. This social engineering tactic allows unauthorized access to critical corporate systems.

Relevant URL: https://www.helpnetsecurity.com/2026/09/08/vishing-microsoft-365-data-theft-extortion/