Threat Intelligence Brief
Curated summary with source attribution
Source: cypro.co.uk
Threat Risk: High
Victim: Uber Freight
Incident: Exfiltration of nearly one million files from Microsoft 365 and Okta environments.
Impact: Potential exposure of sensitive accounts receivable data and corporate communications.
Attacker: Helix Extortion Crew (UNC6671)
Analysis: The attack leverages high-pressure vishing and device code phishing to bypass multi-factor authentication (MFA). By impersonating IT staff, the Helix crew successfully compromised cloud repositories and mailboxes. This incident underscores the ongoing risk of social engineering targeting cloud identity providers.
Recommendations: Enforce FIDO2-compliant hardware security keys to mitigate device code phishing; Implement strict vishing awareness training focusing on IT helpdesk impersonation; Enable aggressive monitoring for anomalous login patterns within Okta and M365 environments
Source: Cypro
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source