Phishing Hits M365; Deepfake Vishing Targets Funds

Security Week Feed · Medium sophistication
Last updated August 7, 2026

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be recreated for security awareness simulations.

Key findings

  • IEH Corporation reports an employee mailbox compromise that started with a phishing message impersonating a prospective business contact and a fake login page.
  • Attackers could view mailbox content including purchase orders and engineering files during the access window, though the firm found no evidence of outbound emails or confirmed exfiltration.
  • A wave of vishing targeted large hedge funds/private equity firms using voice-mimicking technology to trick staff into granting access or disclosing information.
  • Two Sigma reported it blocked the attempt with no impact; Point72 reported reviewing an incident with no initial evidence of client data theft.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance (hedge funds/private equity), IT helpdesk / IAM teams, Sales/Business development, Procurement, Engineering, Executive assistants.
  • Affected industries: Finance (hedge funds/private equity), Manufacturing (defense/aerospace components), Transportation/Ports and logistics.
  • Attack channels: email, website, vishing.
  • Impersonated: Prospective business contact (external partner/vendor), Trusted internal leader or known colleague (voice-mimicked).

Awareness takeaways

  • Treat unexpected “new business contact” emails as high-risk and verify the sender via a trusted channel before clicking or logging in.
  • Never enter work credentials after following a link from an unsolicited message; navigate to Microsoft 365/SSO by typing the known URL or using a bookmark.
  • For phone-based requests, require a callback to a known number or an out-of-band verification step, especially for access approvals or sensitive information.
  • Train staff that “voice sounds right” is no longer proof of identity; deepfake/voice-mimic fraud is being used in real attacks.

Red flags to watch for

  • Unexpected request to log in from an unsolicited contact
  • Login page is not the real Microsoft 365 domain/SSO portal
  • Message creates urgency or pressure to respond to a new 'business contact' quickly
  • Caller insists on bypassing normal verification steps
  • Requests for access approvals or sensitive data over the phone
  • Unusual urgency or secrecy, especially tied to senior leadership
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: one click on a “new business contact” email, and your entire mailbox is wide open. That’s what hit IEH Corporation: a phishing email posing as a prospective business contact, leading to a fake Microsoft 365 login where the user typed their password, letting someone quietly read emails, purchase orders, even engineering files. Now add this twist: funds like Two Sigma and Point72 are getting phone calls where the voice sounds exactly like a senior leader, because it’s being mimicked, to pressure staff into granting access or sharing data. The voice sounds right, but the caller isn’t. Your move: if a new contact email or a phone request sends you to a login or asks for access, stop and use your own route, type our Microsoft 365 or SSO URL yourself or call back on a known number before you do anything.

Similar attacks

Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026
Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026