Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Recorded: Sept. 10, 2026, 9:09 p.m.
| Original | Summarized |
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsCybersecurity OperationsEU Cyber Resilience Act to Enforce New Reporting RequirementsEU Cyber Resilience Act to Enforce New Reporting RequirementsbyNate NelsonSep 10, 20264 Min ReadApplication SecurityMythos Vulnerability Firehose Hits a Human BottleneckMythos Vulnerability Firehose Hits a Human BottleneckbyJai VijayanSep 9, 20264 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryThreat IntelligenceСloud SecurityEndpoint SecurityRemote WorkforceNewsVoice Callers Exploit BYOD to Reach Microsoft 365, Corporate DataThreat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.Nate Nelson,Contributing WriterSeptember 10, 20265 Min ReadSource: Tero Vesalainen via Getty ImagesInitial access brokers (IABs) are phishing employees by calling or texting their personal devices, then exploiting the Microsoft Graph API to perform large-scale corporate data exfiltration.It's almost unavoidable that, in general corporate settings, employees will use personal devices to access company resources. Only the most careful government, research, and other high-value organizations ban it entirely, and most security-forward organizations allow it insofar as employees don't use personal devices to engage with sensitive resources. Even this reasonable latter policy is being tested, though, by attackers who know how to maximize seemingly low-risk attack paths.Since May, Microsoft researchers have tracked at least two threat actors — Storm 3032 and Storm-3121, in its nomenclature — exploiting personal devices to totally bypass companies' authentication security protections. Worse: The two Storms are then likely passing on their earned access to extortion groups, including the nettlesome ShinyHunters. (Microsoft however did not connect any known corporate breaches to these initial access campaigns.)Related:Identity-Based AI Attack Threatens Security of Enterprise DataIABs Exploit Personal DevicesIt's intuitive that if an attacker wants to gain access to a corporate system, they should target a corporate account or device connected to it. The problem is that, in doing so, they'll have to face whatever security measures that company has in place to stop them: email security gateways, endpoint detection and response (EDR), what have you.It's arguably far easier, then, to target employees' personal devices. Those — particularly mobile phones — possess few or no security barriers. And anyone who's worked in an office knows that people use their mobile phones in and around their work environments all the time.Recently, threat actors have been calling or texting employees on their own devices, impersonating their employers' IT helpdesks. The pretext of the call is that the employee has to update some means of authenticating to their work accounts — a passkey, multifactor authentication (MFA), or a single sign-on (SSO) configuration — in order to not lose access to their work. Through a link sent to their phones, employees can log into their accounts and restore order.If an employee doesn't shrewdly identify that an important work communication shouldn't reach them this way, they'll likely follow the phishing link to a convincing Microsoft sign-in page. At this point, attackers have been utilizing both adversary-in-the-middle (AiTM) techniques to steal credentials and session tokens, and device code phishing flows.Related:Cybercriminals Hack Brazilian Government Servers to Host Phishing SitesMore significant than any specific detail of the phishing flow is the fact that vanishingly little of it happens on actual corporate systems. As Microsoft recalled in its blog post, "In many investigations, the employee's recollection of a phone call or text message becomes the earliest and sometimes the only evidence explaining how the compromise began. As a result, investigators must often reconstruct the attack by connecting these reports with subsequent sign-ins, device code authentication events, token activity, and authentication method changes."Threat actors have been decking out their phishing attacks with other fine details, too, like malicious domains that combine the names of victims' employers with relevant security phrases like, "company[.]add-passkey[.]com." And in a minority of cases, for added realism — or, perhaps, to reach more privileged employees — the hackers have used one compromised employee account to phish another. Then, having obtained control over a victim employee's identity, they establish persistent access by registering their own MFA devices.Graph API Attack Enables Corporate EnumerationPossibly the most important step in any extortion attack is identifying where valuable information is and how to get there. In their continued attempt to evade corporate security measures, though, threat actors have been avoiding using malware or other suspicious tools in networks. Instead they've been querying the Microsoft Graph API, the shared doorway for all Microsoft cloud services. The Graph API allows permissioned users to inventory users, resources, content, permissions, and other information useful for an attacker wanting a full lay of the land.Related:'Breeze Comet' Tears Into Brazilian & Global Financial SystemsAs Microsoft wrote in its blog post, the Graph API is an all too innocuous tool for doing powerful reconnaissance. "Microsoft Graph abuse rarely appears suspicious when viewed through a single API call. Requests to endpoints such as /users, /groups, or /sites are commonplace in enterprise environments," the researchers wrote. Only when a single identity or application makes a suspicious number of calls — and an organization is capable of identifying and flagging it — might the activity reach the threshold of actionable security intelligence.With an easy way in and a helpful map of their environments, the attackers can proceed to exfiltrating sensitive corporate data. In particular, Microsoft has observed threat actors stealing data associated with SharePoint, OneDrive, and Exchange. Here, too, the threat actors have tended to keep low profiles by avoiding large, conspicuous data transfers, instead downloading small batches of files periodically over longer periods of time.Place Security Restrictions Around Identity PoliciesTo combat Storm 3032, Storm-3121, and groups like them, Microsoft suggested that organizations more actively log and hunt for suspicious application data exfiltration events and batch Graph API calls, and tightly restrict users' Graph permissions in general. When it comes to personal device risk, the researchers advocate for stricter authentication and authorization measures: requiring phishing-resistant MFA for every sign-in, blocking device code authentication flows where it's unnecessary, limiting application access to managed devices, etc.Robert Coles, senior manager of threat intelligence security at Black Duck, seconds the point. "Organizations will get more value from strengthening identity and authentication controls than from trying to eliminate bring your own device (BYOD). Restricting personal device use may reduce some risk, but it's not realistic for most organizations and it wouldn't have stopped the social engineering described here," he says."The attackers didn't compromise the device, they convinced the user to trust them," he notes, so organizations should focus on limiting the damage employees can do if they make a bad decision. "The objective is to make a compromised account much less useful to an attacker."About the AuthorNate NelsonContributing WriterNate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.See more from Nate NelsonWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsCybersecurity Outlook 2027Benchmark Scores Are a False FlagThreat Exposure Analytics: Measuring and Communicating Security RiskBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskWhat We Missed: Delta Flight Disrupted With Wi-Fi HackWhat We Missed: Delta Flight Disrupted With Wi-Fi HackbyRob Wright,Alexander CulafiAug 20, 2026Cyberattacks & Data BreachesAgentic AI Presents New Insider Threat Model for OrgsAgentic AI Presents New Insider Threat Model for OrgsAug 19, 2026Want more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
Threat actors are exploiting the use of personal devices in corporate environments, known as Bring Your Own Device (BYOD), to gain access to Microsoft 365 and sensitive corporate data. Initial access brokers (IABs) initiate these attacks by phishing or calling employees' personal devices, leveraging the inherent security weaknesses of personal mobile phones, which often lack robust security barriers. This vector is exploited to bypass traditional corporate authentication security measures. The process often begins with social engineering, where threat actors impersonate IT helpdesks, prompting employees to follow links that lead to convincing Microsoft sign-in pages. Through adversary-in-the-middle (AiTM) techniques or device code phishing flows, employees unknowingly provide credentials and session tokens. While the flow of data appears to target corporate systems, Microsoft researchers noted that the initial compromise evidence often resides in the employee's recollection of the phone call or text message, requiring investigators to reconstruct the attack by correlating this information with subsequent authentication events and token activities. Threat actors further enhance their persistence by using a single compromised account to phish others and registering their own Multi-Factor Authentication (MFA) devices. A critical element of the extortion process involves identifying the location of valuable information, which threat actors achieve by querying the Microsoft Graph API. This API functions as a shared gateway for all Microsoft cloud services, allowing permissioned users to inventory users, resources, content, and associated permissions—providing attackers with a comprehensive view of the enterprise environment. Although requests to endpoints like /users or /groups are commonplace in enterprise settings, the cumulative effect of specific identity or application activities can signal suspicious behavior. These attackers focus on exfiltrating data related to SharePoint, OneDrive, and Exchange, often preferring to download small batches of files over extended periods to maintain a low profile and evade detection from large, conspicuous data transfers. To mitigate the risks associated with these attacks, Microsoft and security researchers suggest organizations must pivot their defense strategy toward reinforcing identity and authentication controls rather than attempting to eliminate the BYOD policy entirely. They recommend stricter authentication measures, such as implementing phishing-resistant MFA for all sign-ins and blocking unnecessary device code authentication flows. Furthermore, organizations should focus on logging and actively hunting for suspicious data exfiltration events and atypical batch calls to the Graph API. Robert Coles, a senior manager of threat intelligence security at Black Duck, emphasizes that the objective should be to minimize the potential damage an employee can inflict, suggesting that organizations gain more security value from strengthening identity controls than from trying to enforce a total ban on personal devices. This approach focuses on making compromised accounts less useful to attackers. |