Hackers Impersonate IT Support to Steal MFA Credentials from Over 200 Financial Firms
What Happened — A coordinated vishing campaign (UNC6671) posed as corporate IT help‑desk staff, called employees of more than 200 firms—including Blackstone, Bridgewater Associates, CME Group and Moody’s—and directed them to look‑alike MFA enrollment sites. Victims entered passwords and one‑time passcodes, which attackers harvested in real time, then used the compromised accounts to exfiltrate data from Microsoft 365 and Okta environments.
Why It Matters for Compliance & Audit Readiness
- The scenario is a textbook example of a SOC 2 CC6.1 – Logical Access failure: inadequate controls around MFA provisioning and verification.
- Continuous evidence of MFA policy enforcement, privileged‑access monitoring, and incident‑response playbooks is essential to demonstrate audit readiness.
- Security‑awareness training that covers voice‑phishing (vishing) and verification of IT‑support requests directly mitigates this attack vector.
Who Is Affected – Large‑cap asset managers, hedge funds, exchanges, and other financial‑services firms that rely on cloud‑based productivity and identity platforms.
Recommended Actions
- Map MFA provisioning and change‑management processes to SOC 2 CC6.1 and CC6.2 controls; capture evidence of policy enforcement.
- Deploy real‑time MFA change alerts and enforce out‑of‑band verification for any MFA enrollment request.
- Expand security‑awareness curricula to include vishing simulations and mandatory verification of IT‑support calls.
- Implement continuous monitoring of privileged‑account activity in Microsoft 365 and Okta, retaining logs as audit evidence.
Source: Security Affairs
Technical Notes – Attackers used voice‑phishing (vishing) to spoof corporate help‑desk numbers, then hosted credential‑harvesting subdomains such as company.createssopasskey.com. MFA codes were captured live over the phone; subsequent automated tools harvested data from Microsoft 365 and Okta. No specific CVE is involved; the breach hinges on social‑engineering and credential‑theft techniques. Source: same as above