Threat Intelligence

Fake IT Help Desk Calls Used to Steal Corporate Cloud Data, Researchers Warn

The Hacker News · 8 Aug 2026
Key Takeaway Train employees to independently verify any unsolicited IT support calls—especially on personal phones—before granting access or sharing credentials.

Security researchers have identified a cybercriminal group, tracked as UNC6671, running a series of voice phishing (vishing) attacks against employees at financial services, private equity, and professional services companies. The attackers pose as internal IT help desk staff, calling employees directly on their personal phones and claiming an urgent, mandatory security update is required.

By convincing staff they are speaking with legitimate IT support, the attackers manipulate them into granting access or providing credentials, ultimately allowing the group to steal data stored in cloud-based business software (SaaS platforms). This tactic bypasses many traditional security defences because it targets human trust rather than technical vulnerabilities, and the use of personal phone numbers makes it harder for company security teams to detect or block the contact.

This style of attack has become increasingly common, as criminals find it easier to trick a person than to break through firewalls and monitored corporate networks. Businesses that rely on cloud services for sensitive data are particularly attractive targets, especially where staff are not trained to question unexpected IT-related phone calls.

vishing social engineering SaaS security data extortion phishing

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.