UNC6671 Automates Microsoft 365 Data Theft After Hijacking Employee Sessions

By Published On: August 8, 2026

UNC6671 Exploits Human Trust for Automated Microsoft 365 Data Theft

The digital landscape continually presents evolving threats, and a recent campaign orchestrated by the group tracked as UNC6671 underscores the critical importance of human vigilance in cybersecurity. This threat actor is successfully automating Microsoft 365 data theft by first hijacking employee sessions, a process initiated through sophisticated social engineering tactics. Understanding their methodology is crucial for bolstering organizational defenses against these increasingly prevalent and effective attacks.

The Deceptive Initial Contact: The IT Helpdesk Impersonation

UNC6671’s campaign begins not with a sophisticated technical exploit, but with a simple yet highly effective social engineering technique: a phone call. Posing as IT helpdesk personnel, the attackers contact unsuspecting employees, fabricating a sense of urgency. They often claim an “urgent security migration” is underway, pressuring the target to act quickly without independent verification. This tactic leverages the employee’s natural inclination to comply with IT requests, especially when framed as critical for security. The goal is to bypass initial skepticism and prepare the ground for the next stage of their attack.

Session Hijacking Through Fake Sign-in Pages

Following the convincing phone call, UNC6671 directs employees to a counterfeit Microsoft 365 sign-in page. This page is meticulously crafted to mimic the legitimate portal, making it difficult for an untrained eye to spot the deception. When an employee enters their credentials on this fake page, UNC6671 intercepts them. More critically, these attacks are designed not just to steal credentials but to hijack active sessions. By compromising the session, the attackers gain authenticated access to the victim’s Microsoft 365 environment, bypassing multi-factor authentication (MFA) in many cases, especially if session cookies are obtained. This grants them immediate and direct access to sensitive organizational data.

Automated Data Exfiltration and Its Impact

Once UNC6671 has successfully hijacked a session, their operation shifts to an automated data theft phase. The compromised session becomes an entry point, allowing them to systematically exfiltrate data from the victim’s Microsoft 365 tenant. This automation means that a single successful social engineering attempt can lead to a significant and rapid breach of confidential information. The impact of such a breach can range from intellectual property theft and competitive disadvantage to regulatory fines and severe reputational damage. The automated nature of the exfiltration makes detection challenging, as it can occur swiftly and under the guise of a legitimate user session.

Remediation Actions for UNC6671 and Similar Threats

Mitigating the risk posed by UNC6671 and similar session hijacking and social engineering campaigns requires a multi-layered approach focusing on both technological controls and human awareness.

  • Employee Training and Awareness: Conduct regular and comprehensive security awareness training. Emphasize verification procedures for unexpected IT requests, particularly those involving sign-ins or urgent actions. Train employees to identify phishing attempts, suspicious links, and fake login pages.
  • Implement and Enforce Multi-Factor Authentication (MFA): While session hijacking can sometimes bypass MFA, robust MFA solutions (e.g., FIDO2 security keys, app-based authenticators with number matching) significantly increase the difficulty for attackers. Ensure MFA is mandatory for all Microsoft 365 accounts.
  • Conditional Access Policies: Leverage Microsoft 365 Conditional Access policies to restrict access based on location, device compliance, or sign-in risk. For example, block access from unmanaged devices or suspicious geographic locations.
  • Session Monitoring and Anomaly Detection: Implement tools that monitor user sessions and detect unusual activity, such as bulk data downloads, access from new locations, or unusual times of day. Microsoft 365’s auditing features and Azure AD Identity Protection can assist here.
  • Review and Enforce Security Baselines: Regularly audit and enforce security baselines for all Microsoft 365 services. Ensure tenant-wide settings are configured to minimize attack surface.
  • Secure Browsing Practices: Encourage employees to use official links for Microsoft 365 services and to be wary of links received via email, chat, or phone.
  • Incident Response Plan: Have a well-defined incident response plan specifically for credential theft and session hijacking scenarios. This plan should include steps for account isolation, password resets, and session revocation.

The Human Element: Your Strongest Defense

The UNC6671 campaign serves as a stark reminder that even the most sophisticated technological defenses can be undermined by exploiting the human element. The initial phone call, creating a false sense of urgency and trust, is the lynchpin of their operation. Organizations must prioritize robust security awareness programs that empower employees to identify and report suspicious activities. Technology provides the framework, but an informed and vigilant workforce forms the critical front line against these adaptive and persistent threats.

Share this article

Leave A Comment