08/30/2026
One reason modern cyberattacks are becoming so difficult to spot is that many of them no longer rely on breaking into systems in the traditional sense š¦¹
Instead, attackers are learning how to manipulate normal business processes and get people to unknowingly help them.
Microsoft has warned about a group called Storm-2949 doing exactly that through the password reset process used in Microsoft accounts.
The attack starts with information the criminals have already gathered.
Usually things like a personās email address and phone number.
They then trigger a password reset request on the victimās account and, at the same time, place a phone call pretending to be IT support š
The victim receives a genuine Microsoft authentication prompt on their device while the caller calmly explains that they need to approve it to āfixā the issue.
Thatās what makes this attack convincing.
The notification is real. The system is real.
The attacker is abusing a legitimate process and persuading the person to cooperate.
Once the request is approved, the criminals can reset the password, lock the real user out of the account, and begin accessing company information.
In some reported cases, attackers downloaded huge amounts of data from systems like OneDrive because different employees had access to different folders and shared files šļø
MFA stands for Multi-Factor Authentication. Itās the extra security step where you approve a login using your phone, an app,