Vishing and Device-Code Tricks Drive Cloud Takeovers

Help Net Security · High sophistication
Last updated August 6, 2026

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers abused Microsoft’s device-code login flow to trick users into authorizing access.

Key findings

  • Vishing is described as a fast-growing initial access method where attackers impersonate IT support and push victims to enter credentials into fake login pages or approve remote access via legitimate tools.
  • CrowdStrike observed vishing-related intrusions increase 134% between 2024 and 2025, with further acceleration in early 2026.
  • CORDIAL SPIDER and SNARKY SPIDER used vishing to compromise single sign-on (SSO) accounts and then access Microsoft 365 and Google Workspace.
  • Device code phishing is highlighted as a rapidly growing cloud credential technique, abusing Microsoft’s legitimate authentication process to trick users into authorizing malicious logins.
  • Software supply chain attacks included malware hidden in public developer packages (especially npm), impacting downstream users at scale.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT helpdesk / service desk, Cloud administrators (Microsoft 365 / Entra, Google Workspace), Developers / engineering, Security operations.
  • Affected industries: Technology, Financial services, Education (universities and research institutions).
  • Attack channels: vishing, email.
  • Impersonated: Internal IT support staff, Microsoft sign-in / corporate login workflow.

Awareness takeaways

  • Treat unsolicited ‘IT support’ calls as suspicious and verify the request using a known internal number or ticketing system before taking action.
  • Never enter credentials into a login page provided during an unexpected call; instead, navigate to the service using a trusted bookmark or company portal.
  • Be cautious of unexpected Microsoft authentication prompts, especially device-code flows, and do not approve sign-ins you did not initiate.
  • Developers should assume public packages can be malicious and apply stricter dependency controls before installing or updating software components.

Red flags to watch for

  • Unsolicited call claiming to be IT support
  • Pressure to act quickly and approve access
  • Being directed to a login page that is not a known company URL
  • Unexpected authentication request the user did not initiate
  • Instructions to use a device code for a login the user wasn’t trying to perform
  • Message urgency or vague explanation for why authentication is needed
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a fake IT call and one weird Microsoft code, and your SSO is gone in under five minutes. CrowdStrike saw vishing jump 134%, groups like CORDIAL SPIDER and SNARKY SPIDER call saying, “Hi, this is IT support,” then walk you to a fake login or Quick Assist so they can hijack your single sign-on. The new twist is device-code phishing: an email says, “Microsoft sign-in required: use this device code,” and you’re sent to a real microsoft.com page, so when you enter the code, you’re actually approving their login, not yours. Your move: if you didn’t start the login or support request, hang up, close it, and contact IT using our official helpdesk or chat, never the number or link they just gave you.

Similar attacks

Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing + Fake Login Pages Speed Up Takeovers

Vishing + Fake Login Pages Speed Up Takeovers

CrowdStrike’s threat hunting report says attackers are increasingly using phone-based impersonation and trusted login flows to break into cloud email and SaaS quickly. The report highlights vishing callers posing as IT support, pushing employees to sign in via attacker-controlled phishing pages,…

August 4, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026