logo

Attackers call employees’ personal phones to break into Microsoft 365 accounts

ID: e21d2f85-3d88-5ce8-afa9-acca92187df9

STIX ID: report--e21d2f85-3d88-5ce8-afa9-acca92187df9

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Sinisa Markovic

...
...

Microsoft researchers have tracked a social‑engineering campaign since May 2026 where attackers call or text employees impersonating IT, lure them into passkey/MFA update flows that enable AiTM or device‑code compromises, and register their own MFA methods to retain durable access. With persistence established, the actors use Microsoft Graph API to enumerate tenants and quietly collect files and mail from SharePoint, OneDrive, and Exchange at measured rates (capped under ~1,000 items/hour) to avoid detection; activity is attributed to groups including Storm-3121 and Storm-3032 and supports extortion operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.