08/30/2026
One reason modern cyberattacks are becoming so difficult to spot is that many of them no longer rely on breaking into systems in the traditional sense đŚš
Instead, attackers are learning how to manipulate normal business processes and get people to unknowingly help them.
Microsoft has warned about a group called Storm-2949 doing exactly that through the password reset process used in Microsoft accounts.
The attack starts with information the criminals have already gathered.
Usually things like a personâs email address and phone number.
They then trigger a password reset request on the victimâs account and, at the same time, place a phone call pretending to be IT support đ
The victim receives a genuine Microsoft authentication prompt on their device while the caller calmly explains that they need to approve it to âfixâ the issue.
Thatâs what makes this attack convincing.
The notification is real. The system is real.
The attacker is abusing a legitimate process and persuading the person to cooperate.
Once the request is approved, the criminals can reset the password, lock the real user out of the account, and begin accessing company information.
In some reported cases, attackers downloaded huge amounts of data from systems like OneDrive because different employees had access to different folders and shared files đď¸
MFA stands for Multi-Factor Authentication. Itâs the extra security step where you approve a login using your phone, an app, or a code.
Itâs still one of the best protections available, but attacks like this show that security tools are only effective if people understand what theyâre approving.
Cybersecurity increasingly revolves around trust and human behavior rather than purely technical weaknesses.
People are naturally inclined to cooperate when someone sounds professional, calm, and helpful on the phone.
Especially if a real security prompt appears at the same time âźď¸
Thatâs why you need clear internal processes around password resets, account changes, and unexpected authentication requests.
đ¤ If you received a real authentication request while speaking to someone claiming to be support, do you think youâd feel confident spotting whether it was genuine or not?