Vishing + Fake Login Pages Speed Up Takeovers

eSecurity Planet · High sophistication
Last updated August 4, 2026

CrowdStrike’s threat hunting report says attackers are increasingly using phone-based impersonation and trusted login flows to break into cloud email and SaaS quickly. The report highlights vishing callers posing as IT support, pushing employees to sign in via attacker-controlled phishing pages, enabling rapid takeover and data theft in minutes.

Key findings

  • CrowdStrike reported a twofold increase in vishing intrusions in the first half of 2026 compared with late 2025.
  • Threat groups impersonated IT personnel and convinced users to authenticate via adversary-in-the-middle (AiTM) phishing pages.
  • Attackers then accessed Microsoft 365 and Google Workspace; one incident went from takeover to data theft in under five minutes.
  • The report also found a 15-fold increase in OAuth device code phishing abusing legitimate Microsoft authentication workflows.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT helpdesk/service desk, Finance, HR.
  • Affected industries: Technology, Financial services, Academic organizations.
  • Attack channels: vishing, website.
  • Impersonated: Internal IT personnel / Helpdesk.

Awareness takeaways

  • Treat unexpected ‘IT support’ calls as suspicious; verify using a known internal number or ticketing system before taking action.
  • Be cautious of any request to sign in during a phone call, attackers may use lookalike login pages to capture access.
  • Respond fast to suspected account compromise because attackers can steal data within minutes once they get access.
  • Train users on modern ‘legitimate workflow’ scams (like OAuth device code prompts) that can steal cloud tokens without ‘hacking’ a password directly.

Red flags to watch for

  • Unsolicited IT call pressuring immediate authentication
  • Being redirected to a login page as part of a phone call
  • Requests to authenticate that don’t match normal IT processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you pick up the phone and hear, “This is IT personnel calling to help you authenticate.” CrowdStrike saw vishing like this double in 2026. Groups like CORDIAL SPIDER and SNARKY SPIDER pose as IT, then walk you to a “secure” Microsoft 365 or Google Workspace login page. Here’s the trick: they use adversary-in-the-middle phishing pages and OAuth device code prompts that look legit. You type your password, approve the sign-in, and in under five minutes they’re inside your email and files. Aha moment: real IT will never make you log in while you’re on the call. If anyone does, hang up and contact IT using our official helpdesk or ticketing system instead.

Similar attacks

Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Device-Code Phish Bypasses MFA via Real Microsoft Login

Device-Code Phish Bypasses MFA via Real Microsoft Login

Attackers abused Microsoft’s OAuth “device code” sign-in so victims completed a real Microsoft login and MFA, but the resulting session tokens were issued to the attacker. In a documented Microsoft 365 takeover, the attacker used a believable partner-law-firm email thread and a Google Sites lure…

July 22, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 Tricks Staff Into Approving Real Microsoft Logins

Kali365 is a phishing kit that abuses Microsoft’s real “device code” sign-in flow to trick employees into approving attacker-controlled login codes. Once a victim completes authentication on Microsoft’s legitimate page, attackers can receive access and refresh tokens that may grant ongoing access…

August 5, 2026