When a call comes in from someone claiming to be your IT help desk, urging you to update your passkey or risk losing access to your Microsoft 365 account, most employees comply. That instinct is precisely the entry point that threat actors are targeting. In advisory AL26-010, published this year, the Canadian Centre for Cyber Security (CCCS) flagged a marked shift by financially motivated threat actors toward social-engineering-driven initial access, focusing squarely on enterprise identity services and software-as-a-service (SaaS) platforms. Vishing awareness has moved from a training nice-to-have to an operational requirement for any Canadian organization whose work runs in the cloud.
The human layer of cybersecurity is the gap these attackers exploit most reliably. CCCS reports that these campaigns have been active since at least mid-2025, driven by threat actors who have found it faster and cheaper to deceive an employee over the phone than to penetrate a technical control. Building a security awareness program that actually changes behaviour requires understanding exactly how this attack chain works, not just what phishing emails look like.
What the CCCS Advisory Describes
Advisory AL26-010 outlines a multi-step attack pattern: voice phishing to create urgency, brand impersonation to establish trust, credential harvesting through counterfeit login pages delivered by SMS, and deliberate abuse of help-desk processes to make the request feel routine. The goal is to compromise a cloud identity, typically a Microsoft 365 or enterprise single sign-on account, and then move laterally through connected SaaS applications before anyone notices.
CCCS recommends that organizations implement Dedicated Administrative Workstations for privileged access, enforce conditional access policies, monitor identity provider and SaaS logs for anomalous sign-ins, and maintain sufficient log retention for incident investigations. These are sound technical controls, but they do not address the employee who answers the call and cannot recognize that urgency itself is the weapon being used against them.
The Numbers Behind the Threat
The frequency of these attacks is accelerating sharply. CrowdStrike’s 2026 Threat Hunting Report, released in August, found that vishing intrusions doubled in the first half of 2026 compared to the second half of 2025. The same report tracked threat actors CrowdStrike designates as Snarky Spider moving from initial account takeover to full data exfiltration in under five minutes, leaving almost no detection window for a security operations team.
Device code phishing, a related technique in which attackers exploit trusted OAuth 2.0 authentication flows to capture tokens without triggering MFA, increased fifteenfold in the same six-month window. What all of these methods share is a common dependency: a human decision made under pressure, without time to think, and without a trained reflex to stop and verify.
Where Awareness Programs Fall Down
In our work with Crown corporations and Canadian public sector organizations, we consistently see human risk treated as a compliance checkbox rather than an operational discipline. Stories like this one underscore why annual click-through training is not enough when the threat landscape evolves weekly.
The same gap exists across nonprofits and smaller Canadian enterprises. Annual modules on email phishing do not build the muscle memory needed for a live vishing call. Employees who know to hover over a link before clicking have not been trained to hang up on an unsolicited IT request and call the help desk back using a number from the company directory, not one provided by the caller. That single behaviour difference is the one that breaks the attack chain before credentials are ever entered.
Organizations that want to measure this gap before attackers do can add vishing scenarios to their managed phishing simulation programs. A controlled simulation of a help desk call requesting a passkey or SSO update reveals, in a safe environment, exactly how prepared the team actually is.
One Action This Week
The most practical immediate step costs nothing and requires no new technology. Publish a one-page verification protocol for all IT help desk requests and share it in the tools your team uses every day. The protocol should state clearly that no legitimate IT team will ever ask an employee to update credentials during an unsolicited call. Any such request should be handled by ending the call and contacting IT directly through an internal directory. Revisit this protocol quarterly, because attackers adapt their scripts as soon as the previous version stops working.
Sources
- AL26-010: Cyber Criminals Social-Engineering-Enabled Compromise of Enterprise SaaS Environments, Canadian Centre for Cyber Security, 2026
- CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across Modern Adversary Operations, CrowdStrike, August 2026
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data, The Hacker News, September 2026