vishinghigh
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A sophisticated cybercrime group known as UNC6671 is employing vishing attacks, targeting employees' personal phones to steal SaaS data. The attackers impersonate IT support, tricking victims into fraudulent login portals that capture credentials and multi-factor authentication tokens. This allows them to gain access to cloud environments and applications like Microsoft 365 and Okta, deploying scripts for data exfiltration.