CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers abused Microsoft’s device-code login flow to trick users into authorizing access.
Key findings
- Vishing is described as a fast-growing initial access method where attackers impersonate IT support and push victims to enter credentials into fake login pages or approve remote access via legitimate tools.
- CrowdStrike observed vishing-related intrusions increase 134% between 2024 and 2025, with further acceleration in early 2026.
- CORDIAL SPIDER and SNARKY SPIDER used vishing to compromise single sign-on (SSO) accounts and then access Microsoft 365 and Google Workspace.
- Device code phishing is highlighted as a rapidly growing cloud credential technique, abusing Microsoft’s legitimate authentication process to trick users into authorizing malicious logins.
- Software supply chain attacks included malware hidden in public developer packages (especially npm), impacting downstream users at scale.
Who’s being targeted
- Commonly targeted roles: All employees, Executives, IT helpdesk / service desk, Cloud administrators (Microsoft 365 / Entra, Google Workspace), Developers / engineering, Security operations.
- Affected industries: Technology, Financial services, Education (universities and research institutions).
- Attack channels: vishing, email.
- Impersonated: Internal IT support staff, Microsoft sign-in / corporate login workflow.
Awareness takeaways
- Treat unsolicited ‘IT support’ calls as suspicious and verify the request using a known internal number or ticketing system before taking action.
- Never enter credentials into a login page provided during an unexpected call; instead, navigate to the service using a trusted bookmark or company portal.
- Be cautious of unexpected Microsoft authentication prompts, especially device-code flows, and do not approve sign-ins you did not initiate.
- Developers should assume public packages can be malicious and apply stricter dependency controls before installing or updating software components.
Red flags to watch for
- Unsolicited call claiming to be IT support
- Pressure to act quickly and approve access
- Being directed to a login page that is not a known company URL
- Unexpected authentication request the user did not initiate
- Instructions to use a device code for a login the user wasn’t trying to perform
- Message urgency or vague explanation for why authentication is needed
Read the video transcript
Imagine this: a fake IT call and one weird Microsoft code, and your SSO is gone in under five minutes. CrowdStrike saw vishing jump 134%, groups like CORDIAL SPIDER and SNARKY SPIDER call saying, “Hi, this is IT support,” then walk you to a fake login or Quick Assist so they can hijack your single sign-on. The new twist is device-code phishing: an email says, “Microsoft sign-in required: use this device code,” and you’re sent to a real microsoft.com page, so when you enter the code, you’re actually approving their login, not yours. Your move: if you didn’t start the login or support request, hang up, close it, and contact IT using our official helpdesk or chat, never the number or link they just gave you.