Threat Intelligence

Scammers Use Phone Calls and BYOD Devices to Break Into Microsoft 365 Accounts

Dark Reading · 11 Sept 2026
Key Takeaway Train staff to be sceptical of unexpected phone calls requesting account access or verification, and ensure personal devices used for work have strong security controls like multi-factor authentication.

Security researchers have identified threat actors using Microsoft's Graph API, a tool that helps applications interact with Microsoft 365 data, to identify high-value targets within organisations. Once a target is chosen, attackers use voice-based social engineering, essentially phone calls designed to trick employees, to gain a foothold, often through personal or bring-your-own-device (BYOD) devices that connect to corporate systems.

This access is then reportedly passed on to extortion groups, including ShinyHunters, who use the stolen credentials or data access to pressure businesses into paying ransoms or facing data leaks.

The use of BYOD devices as an entry point highlights a growing risk for small and medium businesses that allow staff to use personal phones or laptops for work email and files. These devices often have weaker security controls than company-managed equipment, making them an attractive target for attackers looking for a way into cloud services like Microsoft 365.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.