Attackers call employees’ personal phones to break into Microsoft 365 accounts
ID: e21d2f85-3d88-5ce8-afa9-acca92187df9
STIX ID: report--e21d2f85-3d88-5ce8-afa9-acca92187df9
Feed Name: Help Net Security
Microsoft researchers have tracked a social‑engineering campaign since May 2026 where attackers call or text employees impersonating IT, lure them into passkey/MFA update flows that enable AiTM or device‑code compromises, and register their own MFA methods to retain durable access. With persistence established, the actors use Microsoft Graph API to enumerate tenants and quietly collect files and mail from SharePoint, OneDrive, and Exchange at measured rates (capped under ~1,000 items/hour) to avoid detection; activity is attributed to groups including Storm-3121 and Storm-3032 and supports extortion operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
