← Back to Crime & Security

Cybercriminal Groups Target U.S. Executives in Coordinated Microsoft 365 Extortion Campaign

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

WASHINGTON — A coordinated cyberattack campaign targeting executive-level accounts within the United States has deployed sophisticated social engineering and technical exploits to steal data from Microsoft 365 environments. The operation, detected on September 7, 2026, involves multiple threat actor groups utilizing fake IT help desk calls to harvest credentials and execute session token replay attacks.

Security researchers have identified three distinct entities operating within this campaign: PREY-0058, UNC6671, and a group designated as Cinder. The attack vector begins with impersonators contacting high-level executives under the guise of technical support personnel. Once victims provide login details or grant remote access, attackers harvest valid session tokens. These tokens allow the intruders to bypass standard authentication measures, including multi-factor authentication, by replaying the active session directly into Microsoft 365 portals.

The primary objective of the campaign is data theft followed by extortion. Attackers exfiltrate sensitive corporate information and subsequently threaten to release the data unless a ransom is paid. The scope of the operation indicates a widespread effort focused specifically on C-suite executives, suggesting a strategy designed to maximize leverage against target organizations.

Attribution for the various components of the campaign remains complex. PREY-0058 has been tracked by cybersecurity firm Arctic Wolf, while UNC6671 is a designation assigned by Mandiant, a subsidiary of Google. The involvement of Cinder presents further complexity; some analysts suggest a potential link to operations previously associated with the group Pink, though this connection has not been definitively established. The simultaneous activity of these groups suggests either a collaborative effort or a convergence of tactics among separate criminal enterprises.

The campaign exploits the trust executives place in IT support channels. By mimicking legitimate help desk procedures, attackers bypass human skepticism that might otherwise prevent unauthorized access. Once inside the network, the use of session token replay allows for persistent access without triggering standard login alerts, as the activity appears to originate from a previously authenticated user.

Microsoft 365 administrators are advised to monitor for unusual sign-in patterns and review help desk request logs for anomalies. Organizations are urged to implement strict verification protocols for any unsolicited technical support requests, regardless of the caller's claimed identity.

Questions remain regarding the full extent of the data compromised and whether the groups involved are sharing infrastructure or intelligence. It is unclear if the campaign will expand beyond executive accounts to include broader organizational networks. As investigators analyze the scope of the intrusion, the potential for further extortion attempts looms over affected U.S. companies.

Discussion

0 / 2000