RMON Networks Security Advisory


What You Need to Know


How the Attack Works

Step 1: The Phone Call

  • Internal IT Support

  • Microsoft Support

  • Security Operations

  • Help Desk Personnel

Step 2: The Fake Website

Step 3: Account Compromise

Step 4: Data Theft

  • Email

  • SharePoint

  • OneDrive

  • Teams files

  • Sensitive business documents


Warning Signs Your Team Should Know


What Employees Should Do

STOP

VERIFY

NEVER

  • Share MFA codes

  • Approve unexpected authentication prompts

  • Register new authentication methods at a caller's request

  • Enter credentials on websites provided during unsolicited calls


Recommended Security Controls


If You Suspect a Compromise

  • You approved an unexpected MFA request

  • You entered credentials after receiving a security-related phone call

  • You registered a passkey or authentication method at someone's direction

  • You notice unusual account activity


Need Assistance?

Back to all posts

Have an IT question you want handled?

Talk to a local team that answers when you call and owns the outcome.