security1 publisher
Fake IT callers register their own MFA method under the Microsoft 365 identities they phish
Microsoft has tracked this since May 2026. First contact lands on an unmanaged personal phone, and the attacker's own authenticator outlives the stolen session, so tenant telemetry only starts after the account is already lost.
Publishers:helpnetsecurity.com
Reality
- Evidence55
- Adoption45
- Hype gap−10
- Incentives65
- Confidence58