RFDELTA Signals
Signal 029Free

Vishing and MFA Bypass: How a Phone Call Can Defeat Ordinary Authentication

Google Threat Intelligence says UNC6671 continues to use help-desk voice phishing, spoofed login portals and adversary-in-the-middle infrastructure to intercept credentials and MFA tokens before moving into enterprise SaaS environments.

RFDELTA Signal 029: Vishing MFA BypassRFDELTA SIGNAL 029
The authentication control can be technically sound while the support workflow around it remains socially exploitable.Identity security / social engineering

Why it matters

Modern phishing is not limited to email. Google Threat Intelligence reports that UNC6671 has continued using tailored voice phishing to impersonate IT help-desk personnel and pressure enterprise users through urgent security or authentication pretexts.

The attack path targets both the human process and the identity layer. A believable call can move the victim to infrastructure designed to capture credentials, authentication state or session material.

The initial access channel is often a personal phone

GTIG says UNC6671 frequently contacts employees through personal mobile devices while posing as IT support staff handling mandatory or urgent security migrations. The caller then directs the target to a lookalike login portal.

That makes conventional email filtering only one part of the defensive stack. Organizations also need a trusted way for users to independently verify unexpected support contact before changing authentication settings or entering credentials.

Adversary-in-the-middle infrastructure changes the MFA threat model

The reported campaigns use adversary-in-the-middle, or AiTM, credential-harvesting infrastructure capable of intercepting credentials and MFA tokens. After establishing session persistence, the actors have used automated tooling to extract data from enterprise cloud services including Microsoft 365 and Okta.

This does not mean all MFA is ineffective. It means authentication methods that can be replayed or proxied through a lookalike site provide less protection against an attacker operating in the middle of the session.

Phishing-resistant authentication removes a major part of the attack path

GTIG recommends phishing-resistant authenticators such as FIDO2 security keys, passkeys and platform authenticators. WebAuthn-based origin binding helps prevent a credential from being successfully used through an attacker-controlled lookalike domain or AiTM proxy.

The same guidance also recommends tighter session controls, trusted network sources, managed-device requirements and monitoring for unusual identity-provider events and scripted SaaS access.

Help-desk verification is a security control

Technical authentication controls work best when the human support process is equally explicit. Users should have a known out-of-band channel for verifying unexpected IT contact, especially when the caller requests an MFA change, passkey enrollment, credential entry or urgent access action.

A resilient process assumes the attacker may already know enough about the organization to sound credible.

The RFDELTA takeaway

Identity security is a system, not a login box. The strongest defense combines phishing-resistant authentication with controlled sessions, managed endpoints, identity telemetry and a support-verification process that does not depend on trusting the inbound caller.

Watch the original Signal

The concise video version is designed for discovery; this page preserves the sourcing, caveats and deeper context.

Memorable path: https://rfdelta.com/029

Video transcript

An unexpected call from IT can still defeat ordinary MFA. Google says UNC6671 targets employees on personal phones while posing as help-desk staff. Victims are sent to spoofed portals where adversary-in-the-middle infrastructure can intercept credentials and MFA tokens. Stolen sessions can then provide access to services such as Microsoft 365 and Okta and support automated data theft. Move high-value users to phishing-resistant authentication and verify unexpected help-desk contact through a separate trusted channel. Follow InfoSec for actionable threat intelligence.

Frequently asked questions

What is vishing?

Vishing is voice phishing: social engineering conducted by phone or voice communication to manipulate a target into taking an unsafe action.

Does this mean MFA does not work?

No. GTIG specifically recommends phishing-resistant MFA such as FIDO2/WebAuthn-based authenticators. The reported campaigns exploit users and authentication flows that can be proxied or intercepted through attacker-controlled infrastructure.

What controls help disrupt this attack path?

Phishing-resistant authentication, tighter session controls, managed-device requirements, identity-provider monitoring and an independent process for verifying unexpected help-desk contact all reduce the attack surface.

Primary sources

Continue exploring RFDELTA

RFDELTA Signals map the hidden systems, technology transitions and operational dependencies underneath fast-moving headlines.