logo

Pink Extortion Group Emerges Targeting Microsoft 365 Data

ID: f74594e6-8d10-5a19-b02e-e9babf5698e0

STIX ID: report--f74594e6-8d10-5a19-b02e-e9babf5698e0

Feed Name: The Cyber Express

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Mihir Bagwe

...
...

Unit 42 reports a new extortion brand called “Pink” (cluster CL-CRI-1147) that uses vishing to harvest Microsoft 365 credentials, then rapidly exfiltrates data from SharePoint/OneDrive via Microsoft Graph and automated requests before leveraging compromised accounts to send internal extortion messages; researchers observed multiple victim listings on a leak site and identified phishing domains and IPs tied to the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.