30/08/2026
One reason modern cyber attacks are becoming so difficult to spot is that many of them no longer rely on breaking into systems in the traditional sense 🦹
Instead, attackers are learning how to manipulate normal business processes and get people to unknowingly help them.
Microsoft has warned about a group called Storm-2949 doing exactly that through the password reset process used in Microsoft accounts.
The attack starts with information the criminals have already gathered.
Usually things like a person’s email address and phone number.
They then trigger a password reset request on the victim’s account and, at the same time, place a phone call pretending to be IT support 📞
The victim receives a genuine Microsoft authentication prompt on their device while the caller calmly explains that they need to approve it to “fix” the issue.
That’s what makes this attack convincing.
The notification is real. The system is real.
The attacker is abusing a legitimate process and persuading the person to cooperate.
Once the request is approved, the criminals can reset the password, lock the real user out of the account, and begin accessing company information.
In some reported cases, attackers downloaded huge amounts of data from systems like OneDrive because different employees had access to different folders and shared files 🗂️
MFA stands for Multi-Factor Authentication. It’s the extra security step where you approve a login using your phone, an app, or a code.
It’s still one of the best protections available, but attacks like this show that security tools are only effective if people understand what they’re approving.
Cyber security increasingly revolves around trust and human behaviour rather than purely technical weaknesses.
People are naturally inclined to cooperate when someone sounds professional, calm, and helpful on the phone.
Especially if a real security prompt appears at the same time ‼️
That’s why you need clear internal processes around password resets, account changes, and unexpected authentication requests.
🤔 If you received a real authentication request while speaking to someone claiming to be support, do you think you’d feel confident spotting whether it was genuine or not?