Personal Phones Bypass SaaS Controls in UNC6671 Wave

UNC6671 is getting past corporate device controls by reaching employees on personal phones and stealing a live MFA session, not by breaking the cloud service itself. That makes the approved login path the access point for Microsoft 365, Okta, and other SaaS data. Google Threat Intelligence Group and Mandiant tied the activity to vishing and adversary-in-the-middle phishing aimed at financial services, private equity, and professional services firms. The group poses as IT help desk staff, captures credentials and MFA tokens, then uses automated scripts to persist and exfiltrate data from Microsoft 365 and Okta. The risk is not limited to the initial login. Once the attacker has a live SaaS session, patching endpoints does not undo the cloud access they already took.

Part of the PlainSec briefing for 2026-08-08

Editions

Sources