Your CFO gets a call. The caller ID looks internal. The voice on the line sounds like IT, references a real ongoing project, and asks for help resolving an urgent login issue — maybe a one-time code, maybe a quick approval on a push notification that just came through. It takes ninety seconds. There's no malware, no suspicious link, no attachment to scan. And by the time anyone realizes what happened, the attacker is already inside a Microsoft 365 account with executive-level access.
This is the pattern behind a wave of recent campaigns targeting leadership at organizations across industries, and it's worth paying attention to for one uncomfortable reason: it doesn't fail because your MFA is broken. It fails because MFA was never designed to stop a human being from being convinced to help.
Security awareness training tends to focus on phishing emails — suspicious links, spoofed domains, urgent subject lines. Most executives have sat through that training. Fewer have been trained to be suspicious of a phone call that sounds exactly like their own IT department, because historically, that call was always legitimate.
Attackers running these campaigns understand something about executive culture: senior leaders are used to being helped quickly, not questioned. They don't typically call the help desk — the help desk calls them, or someone escalates on their behalf. That inverted relationship is exactly what makes a convincing vishing call land. Add in a caller who already knows the executive's name, title, and a plausible recent IT initiative — information that's often just sitting on LinkedIn or in a company directory — and the call clears the bar for "sounds legitimate" without much effort at all.
The technical piece that makes this dangerous rather than just annoying is adversary-in-the-middle token theft. Instead of trying to guess a password, the attacker relays a real login session in real time — the target enters real credentials into what looks like a real login page, approves what looks like a real MFA prompt, and the attacker captures the resulting session token. From that point, the attacker isn't guessing anything. They have a live, authenticated session, indistinguishable on the back end from the executive's own device.
It's tempting to respond to this kind of threat with another technical control — stronger MFA, stricter conditional access policies, phishing-resistant hardware keys. Those are genuinely useful, and if your organization hasn't moved toward phishing-resistant authentication for high-privilege accounts, that's a real gap worth closing. But the technology alone won't fix the underlying problem, because the attack doesn't target the technology. It targets the process around it — specifically, the fact that most organizations have never clearly defined what a legitimate help desk interaction is supposed to look like, and executives are the group least likely to have been walked through it.
Ask yourself honestly: does your CFO know what your help desk will and won't ask for over the phone? Does your VP of Sales know there's a callback verification process before any credential reset happens? If the answer is "probably not," that's not a training failure specific to any one person — it's a gap in how the organization has defined and communicated its own identity verification process, top to bottom.
The organizations handling this well aren't relying on awareness training alone, and they're not relying on technology alone either. They're treating it as a process problem with a technical backstop:
None of this requires ripping out existing infrastructure. It requires treating executive identity risk as its own category, separate from general employee security awareness, and closing the specific process gaps that these campaigns are built to exploit.
October is Cybersecurity Awareness Month, and most organizations will run some version of the same phishing-simulation-and-poster campaign they run every year. That's not wrong, but it's aimed at the wrong altitude for this particular risk. The people most likely to be targeted by a convincing vishing call aren't the general employee population — they're the small group of people with access valuable enough to be worth calling directly. If your awareness planning for October doesn't include a specific conversation with that group, this is the gap to close before the campaigns targeting them get more sophisticated, not less.
This threat succeeds by exploiting trust and process gaps, not software vulnerabilities — which means the fix has to start in the same place. A callback verification process that any executive can follow without needing to be a security expert, phishing-resistant authentication where it matters most, and a clear-eyed look at who in your organization is worth a phone call from someone pretending to be IT.