logo

Why Attackers Are Bypassing Phishing Emails and Targeting Identity Instead

ID: 07d47cef-acfe-5aff-a95f-0871d6275593

STIX ID: report--07d47cef-acfe-5aff-a95f-0871d6275593

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-04-28

Author: Jamie Mamroe

...
...

This report describes 'Okta vishing', a rising voice-based social engineering technique where attackers call users or help desks to manipulate MFA and SSO settings, gain access to identity providers, and pivot into cloud SaaS (Microsoft 365, SharePoint, OneDrive, Google Workspace, Slack, etc.) for large-scale data exfiltration; it details an attack flow, key DFIR indicators (MFA resets, new device enrollments, abnormal SharePoint/OneDrive downloads, OAuth app consent), and mitigations including phishing-resistant MFA, strict help-desk verification, conditional access, identity logging/monitoring, and SOC/MDR alignment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.