The Com Threat Groups Target Critical Infrastructure Data Theft | MSSP Advisory
Critical
DateMay 1, 2026
📋Executive Summary
Two threat groups linked to The Com are targeting critical infrastructure through voice-phishing and social engineering attacks that breach identity platforms and move laterally through SaaS environments. CrowdStrike reports these financially-motivated attackers share tactics with Scattered Spider and focus on data theft operations. The attacks specifically target identity platforms as the initial compromise vector before pivoting to SaaS applications.
⚠️Why It Matters for MSSPs
Your identity platforms and SaaS tools that authenticate to client environments are direct targets for these voice-phishing campaigns. If they compromise your Microsoft 365, PSA, or RMM authentication, they get keys to every client network you manage. Your clients running critical infrastructure face the same identity platform vulnerabilities and expect you to warn them about social engineering attacks targeting their IT teams.
✅Recommended Action
Audit your identity platform configurations within 24 hours and enable conditional access policies that block logins from unrecognized devices or locations for all admin accounts accessing client environments.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Identity Access
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.