Voicemail Phish Steals Microsoft 365 Sessions

The Hacker News · High sophistication
Last updated August 7, 2026

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in payment workflows, while using residential proxy logins to blend in.

Key findings

  • Campaign uses “voicemail-themed phishing emails” to lure victims to adversary-in-the-middle (AitM) pages that proxy Microsoft login and capture credentials and MFA codes.
  • Attackers use a multi-step redirection chain through trusted services (Google/Google Meet/Google Ads/Amazon S3) to evade reputation-based filtering.
  • After compromise, activity focuses on identifying payroll/HR/finance staff and collecting messages related to payroll, invoices, payments, banking, and benefits.
  • Residential proxies and geolocation matching are used so malicious sign-ins appear to originate from the victim’s country; sessions are refreshed automatically about every eight hours.
  • In some cases, attackers created inbox rules to hide evidence by moving messages to Deleted Items and marking them read.

Who’s being targeted

  • Commonly targeted roles: All employees, Payroll, HR, Finance/AP/AR, IT helpdesk, Security/IT administrators.
  • Affected industries: Healthcare, Education, Manufacturing, Government, Professional services.
  • Attack channels: email, website.
  • Impersonated: Voicemail/Unified Messaging system (generic corporate voicemail notification), Legitimate user (attacker using the victim’s existing Microsoft 365 session).

Awareness takeaways

  • Treat voicemail-themed emails as high-risk and only access voicemail through known, trusted methods (bookmark/app), not embedded links.
  • Be cautious of login pages reached via multiple redirects; trusted-brand redirects (Google/AWS) can still lead to phishing.
  • Train payroll/HR/finance teams that attackers may first silently monitor mailboxes for payment processes before attempting fraud, report unusual access early.
  • Watch for hidden-cover tracks like inbox rules moving messages to Deleted Items or marking them read, and report immediately.

Red flags to watch for

  • Voicemail email pushes you to sign in via a link instead of using the normal Microsoft 365 portal/app
  • Multiple redirects through unrelated trusted services before reaching a login page
  • Login page behaves like a proxy and asks for MFA code during an unexpected “voicemail” flow
  • Unexpected sign-ins that appear local but use unusual browsers/user agents (e.g., Outlook client with Firefox/Python Requests)
  • Recurring sign-ins at regular intervals (about every 8 hours)
  • Inbox rules that move messages to Deleted Items and mark them as read
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this email: “New voicemail message, sign in to listen.” Looks normal, right? It’s actually a trap for your Microsoft 365 account. You click the voicemail link, it bounces through Google Meet, Google Ads, even an Amazon S3 URL, then lands on a perfect-looking Microsoft login page that asks for your password and MFA code. That’s an adversary-in-the-middle page quietly stealing your entire session. Once they’re in, they reuse your session from residential proxies that look local, quietly search payroll, HR, and finance mailboxes, and even drop inbox rules that move certain emails to Deleted Items and mark them read so you never see the signs. Here’s the move: treat every voicemail email as high risk. If you get one, don’t click the link, open your usual Microsoft 365 or phone app directly and check voicemail there instead.

Similar attacks

Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Phished npm Maintainer Led to Debug/Chalk Hijack

Phished npm Maintainer Led to Debug/Chalk Hijack

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through a lookalike npm domain. After gaining that trusted access, the attackers published malicious updates that altered crypto wallet…

July 30, 2026