Phishing Hits M365; Deepfake Vishing Targets Funds

Security Week Feed · Medium sophistication
Last updated August 7, 2026

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be recreated for security awareness simulations.

Key findings

  • IEH Corporation reports an employee mailbox compromise that started with a phishing message impersonating a prospective business contact and a fake login page.
  • Attackers could view mailbox content including purchase orders and engineering files during the access window, though the firm found no evidence of outbound emails or confirmed exfiltration.
  • A wave of vishing targeted large hedge funds/private equity firms using voice-mimicking technology to trick staff into granting access or disclosing information.
  • Two Sigma reported it blocked the attempt with no impact; Point72 reported reviewing an incident with no initial evidence of client data theft.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance (hedge funds/private equity), IT helpdesk / IAM teams, Sales/Business development, Procurement, Engineering, Executive assistants.
  • Affected industries: Finance (hedge funds/private equity), Manufacturing (defense/aerospace components), Transportation/Ports and logistics.
  • Attack channels: email, website, vishing.
  • Impersonated: Prospective business contact (external partner/vendor), Trusted internal leader or known colleague (voice-mimicked).

Awareness takeaways

  • Treat unexpected “new business contact” emails as high-risk and verify the sender via a trusted channel before clicking or logging in.
  • Never enter work credentials after following a link from an unsolicited message; navigate to Microsoft 365/SSO by typing the known URL or using a bookmark.
  • For phone-based requests, require a callback to a known number or an out-of-band verification step, especially for access approvals or sensitive information.
  • Train staff that “voice sounds right” is no longer proof of identity; deepfake/voice-mimic fraud is being used in real attacks.

Red flags to watch for

  • Unexpected request to log in from an unsolicited contact
  • Login page is not the real Microsoft 365 domain/SSO portal
  • Message creates urgency or pressure to respond to a new 'business contact' quickly
  • Caller insists on bypassing normal verification steps
  • Requests for access approvals or sensitive data over the phone
  • Unusual urgency or secrecy, especially tied to senior leadership
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: one click on a “new business contact” email, and your entire mailbox is wide open. That’s what hit IEH Corporation: a phishing email posing as a prospective business contact, leading to a fake Microsoft 365 login where the user typed their password, letting someone quietly read emails, purchase orders, even engineering files. Now add this twist: funds like Two Sigma and Point72 are getting phone calls where the voice sounds exactly like a senior leader, because it’s being mimicked, to pressure staff into granting access or sharing data. The voice sounds right, but the caller isn’t. Your move: if a new contact email or a phone request sends you to a login or asks for access, stop and use your own route, type our Microsoft 365 or SSO URL yourself or call back on a known number before you do anything.

Similar attacks

Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026