HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Hackers Impersonate IT Support to Steal MFA Credentials from Over 200 Financial Firms

A vishing campaign targeting more than 200 financial institutions used fake IT‑help‑desk calls to harvest MFA credentials, then accessed Microsoft 365 and Okta to steal data. The breach highlights gaps in SOC 2 access‑control policies and the need for robust MFA verification and security‑awareness training.

LiveThreat™ Intelligence · 📅 August 08, 2026· 📰 securityaffairs.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Hackers Impersonate IT Support to Steal MFA Credentials from Over 200 Financial Firms

What Happened — A coordinated vishing campaign (UNC6671) posed as corporate IT help‑desk staff, called employees of more than 200 firms—including Blackstone, Bridgewater Associates, CME Group and Moody’s—and directed them to look‑alike MFA enrollment sites. Victims entered passwords and one‑time passcodes, which attackers harvested in real time, then used the compromised accounts to exfiltrate data from Microsoft 365 and Okta environments.

Why It Matters for Compliance & Audit Readiness

  • The scenario is a textbook example of a SOC 2 CC6.1 – Logical Access failure: inadequate controls around MFA provisioning and verification.
  • Continuous evidence of MFA policy enforcement, privileged‑access monitoring, and incident‑response playbooks is essential to demonstrate audit readiness.
  • Security‑awareness training that covers voice‑phishing (vishing) and verification of IT‑support requests directly mitigates this attack vector.

Who Is Affected – Large‑cap asset managers, hedge funds, exchanges, and other financial‑services firms that rely on cloud‑based productivity and identity platforms.

Recommended Actions

  • Map MFA provisioning and change‑management processes to SOC 2 CC6.1 and CC6.2 controls; capture evidence of policy enforcement.
  • Deploy real‑time MFA change alerts and enforce out‑of‑band verification for any MFA enrollment request.
  • Expand security‑awareness curricula to include vishing simulations and mandatory verification of IT‑support calls.
  • Implement continuous monitoring of privileged‑account activity in Microsoft 365 and Okta, retaining logs as audit evidence.

Source: Security Affairs

Technical Notes – Attackers used voice‑phishing (vishing) to spoof corporate help‑desk numbers, then hosted credential‑harvesting subdomains such as company.createssopasskey.com. MFA codes were captured live over the phone; subsequent automated tools harvested data from Microsoft 365 and Okta. No specific CVE is involved; the breach hinges on social‑engineering and credential‑theft techniques. Source: same as above

📰 Original Source
https://securityaffairs.com/196800/security/hackers-impersonate-it-support-to-breach-leading-financial-companies.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →