Rejuvenate IT Logo

Attackers phoned staff pretending to be IT support – and got straight into the company Microsoft accounts

The extortion group ShinyHunters has published 10.9 million unique email addresses stolen from Abbott’s cancer diagnostics arm, Exact Sciences, according to The Register. Names, postal addresses, phone numbers, dates of birth and health information went with them.

There was no clever exploit behind it. The attackers picked up the telephone. Security firm CybelAngel reports that calls to employees in mid-June persuaded at least one of them to sign in on a lookalike login page, handing over the details for their Microsoft Entra account – the single sign-in that opens everything else.

Abbott has confirmed the intruders reached Microsoft Entra, ServiceNow, SharePoint, Databricks and Coupa, and says the affected environment – legacy Exact Sciences systems inherited through an acquisition – was kept apart from its core systems, with no effect on patient services. ShinyHunters claims a far larger haul, including 30 million records and a million US social security numbers. Abbott disputes some of that framing, and those bigger numbers remain the attackers’ word rather than anyone’s finding.

Who this affects

You are not a multi-billion-pound medical company, and this is not your industry. It is still worth two minutes of your time, because the method works just as well on a business of twenty people. You almost certainly have Microsoft 365, you probably have single sign-on, and you definitely have at least one helpful member of the team who would not want to be awkward with somebody from IT.

That is the entire attack. No malware, no unpatched server, nothing for a firewall to inspect or an antivirus to quarantine – a convincing phone call and a login page that looks right. A small business is an easier target here, not a harder one: your team knows exactly who looks after the IT, which makes that person easier to impersonate. And as Abbott’s own list shows, one compromised sign-in does not stay in one place. Whatever that account can open, the caller can open too.

What to put in place this week

  • Set one rule and tell everyone. Nobody from IT – ours or anyone’s – will ring out of the blue and ask you to sign in, approve a prompt or read out a code. If a call asks for any of that, hang up and ring back on the number you already had.
  • Look at anything a phone call can trigger. CybelAngel’s first recommendation is to review help desk verification for any process that can be started by phone. Password resets and re-registering multi-factor authentication are the two that matter. Agree with your IT partner how a caller gets identified before anything is reset.
  • Move off typed codes where you can. A six-digit code can be read aloud to a stranger. App approval with number matching, or a physical security key, cannot be handed over the same way.
  • Know what hangs off your single sign-on. If one login opens your email, your files and your finance system, that login deserves the strongest protection you have, plus clear rules about who can sign in and from where.
  • If you have bought a business, know what came with it. The systems breached here were inherited ones. Kit acquired with a company is rarely anybody’s first priority, which is exactly why it is worth an hour of yours.

Worth a conversation

No product would have stopped this one. The employee did what they were asked by someone who sounded plausible. What helps is a team that has been shown the trick before it arrives, and accounts hardened enough that one slip is not the end of it.

That is what our security awareness training and Microsoft 365 protection are for – the first so the call gets put down, the second so a stolen sign-in is spotted if it is not. Both are watched round the clock by people, not just software.

Call us on 01202 237 273 or book a call.