Fake help desk calls coming for your Microsoft 365
Attackers are impersonating IT help desks to trick Microsoft 365 users, especially executives, into handing over access that can be used for data theft and extortion.
You may get an unexpected call from someone claiming to be from your IT help desk or Microsoft support, saying there is a problem with your Microsoft 365 account that needs urgent attention. They sound convincing, know your role, and push you to follow sign-in steps while they stay on the line. In some cases, they direct you to a real-looking Microsoft login page or talk you through a security check that feels routine.
What gives it away is not one dramatic mistake, but the way the process is controlled by the caller, not by your organisation. The attackers are using adversary-in-the-middle pages to sit between you and the real Microsoft 365 sign-in, which means they can capture what you enter and even reuse a valid session. They also use residential proxy sign-ins, so the follow-up access can look like it is coming from an ordinary home internet connection rather than an obvious criminal network.
They are after your Microsoft 365 access, not just your password. If you engage, they can steal session tokens, sign in as you, reach email and cloud data, and then use what they find for theft and extortion. For NZ businesses, that can mean sensitive messages, files, and internal discussions being exposed or used to pressure your organisation.
This activity is specifically targeting senior staff such as directors, vice presidents, and other executives because those accounts often hold broader access and more sensitive information. If your business relies on Microsoft 365 or other SaaS platforms, you should treat unsolicited help desk calls about urgent account issues as high risk until independently verified.
Source: The Hacker News β https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Hang up and call the organisation back using a phone number sourced independently from its official website or your internal contact list.
- Do not: Provide passwords, PINs, one-time codes, or remote access during an unsolicited call, even if the caller sounds legitimate.
- Do not: Stay on the line while the caller walks you through sign-in or identity checks. Genuine organisations will not require that.
- Report: Report suspicious calls to NCSC NZ at report.ncsc.govt.nz, and if any financial details were disclosed, contact the relevant bank immediately.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.

