Scammers Use Phone Calls and BYOD Devices to Break Into Microsoft 365 Accounts
Security researchers have identified threat actors using Microsoft's Graph API, a tool that helps applications interact with Microsoft 365 data, to identify high-value targets within organisations. Once a target is chosen, attackers use voice-based social engineering, essentially phone calls designed to trick employees, to gain a foothold, often through personal or bring-your-own-device (BYOD) devices that connect to corporate systems.
This access is then reportedly passed on to extortion groups, including ShinyHunters, who use the stolen credentials or data access to pressure businesses into paying ransoms or facing data leaks.
The use of BYOD devices as an entry point highlights a growing risk for small and medium businesses that allow staff to use personal phones or laptops for work email and files. These devices often have weaker security controls than company-managed equipment, making them an attractive target for attackers looking for a way into cloud services like Microsoft 365.