Fake IT Help Desk Calls Used to Steal Corporate Cloud Data, Researchers Warn
Security researchers have identified a cybercriminal group, tracked as UNC6671, running a series of voice phishing (vishing) attacks against employees at financial services, private equity, and professional services companies. The attackers pose as internal IT help desk staff, calling employees directly on their personal phones and claiming an urgent, mandatory security update is required.
By convincing staff they are speaking with legitimate IT support, the attackers manipulate them into granting access or providing credentials, ultimately allowing the group to steal data stored in cloud-based business software (SaaS platforms). This tactic bypasses many traditional security defences because it targets human trust rather than technical vulnerabilities, and the use of personal phone numbers makes it harder for company security teams to detect or block the contact.
This style of attack has become increasingly common, as criminals find it easier to trick a person than to break through firewalls and monitored corporate networks. Businesses that rely on cloud services for sensitive data are particularly attractive targets, especially where staff are not trained to question unexpected IT-related phone calls.