Vishing and Device-Code Tricks Drive Cloud Takeovers

Help Net Security · High sophistication
Last updated August 6, 2026

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers abused Microsoft’s device-code login flow to trick users into authorizing access.

Key findings

  • Vishing is described as a fast-growing initial access method where attackers impersonate IT support and push victims to enter credentials into fake login pages or approve remote access via legitimate tools.
  • CrowdStrike observed vishing-related intrusions increase 134% between 2024 and 2025, with further acceleration in early 2026.
  • CORDIAL SPIDER and SNARKY SPIDER used vishing to compromise single sign-on (SSO) accounts and then access Microsoft 365 and Google Workspace.
  • Device code phishing is highlighted as a rapidly growing cloud credential technique, abusing Microsoft’s legitimate authentication process to trick users into authorizing malicious logins.
  • Software supply chain attacks included malware hidden in public developer packages (especially npm), impacting downstream users at scale.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT helpdesk / service desk, Cloud administrators (Microsoft 365 / Entra, Google Workspace), Developers / engineering, Security operations.
  • Affected industries: Technology, Financial services, Education (universities and research institutions).
  • Attack channels: vishing, email.
  • Impersonated: Internal IT support staff, Microsoft sign-in / corporate login workflow.

Awareness takeaways

  • Treat unsolicited ‘IT support’ calls as suspicious and verify the request using a known internal number or ticketing system before taking action.
  • Never enter credentials into a login page provided during an unexpected call; instead, navigate to the service using a trusted bookmark or company portal.
  • Be cautious of unexpected Microsoft authentication prompts, especially device-code flows, and do not approve sign-ins you did not initiate.
  • Developers should assume public packages can be malicious and apply stricter dependency controls before installing or updating software components.

Red flags to watch for

  • Unsolicited call claiming to be IT support
  • Pressure to act quickly and approve access
  • Being directed to a login page that is not a known company URL
  • Unexpected authentication request the user did not initiate
  • Instructions to use a device code for a login the user wasn’t trying to perform
  • Message urgency or vague explanation for why authentication is needed
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a fake IT call and one weird Microsoft code, and your SSO is gone in under five minutes. CrowdStrike saw vishing jump 134%, groups like CORDIAL SPIDER and SNARKY SPIDER call saying, “Hi, this is IT support,” then walk you to a fake login or Quick Assist so they can hijack your single sign-on. The new twist is device-code phishing: an email says, “Microsoft sign-in required: use this device code,” and you’re sent to a real microsoft.com page, so when you enter the code, you’re actually approving their login, not yours. Your move: if you didn’t start the login or support request, hang up, close it, and contact IT using our official helpdesk or chat, never the number or link they just gave you.

Similar attacks

Vishing + Fake Login Pages Speed Up Takeovers

Vishing + Fake Login Pages Speed Up Takeovers

CrowdStrike’s threat hunting report says attackers are increasingly using phone-based impersonation and trusted login flows to break into cloud email and SaaS quickly. The report highlights vishing callers posing as IT support, pushing employees to sign in via attacker-controlled phishing pages,…

August 4, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 is a phishing kit that abuses Microsoft’s real “device code” sign-in flow to trick employees into approving attacker-controlled login codes. Once a victim completes authentication on Microsoft’s legitimate page, attackers can receive access and refresh tokens that may grant ongoing access…

August 5, 2026