M365 Phishing via Personal Phones
PUBLISHED Sep 10, 2026, 11:03 AM ET
Microsoft Security Research disclosed that threat actors launched a widespread social engineering campaign targeting enterprise employees on personal mobile phones to compromise Microsoft 365 cloud accounts. Attackers posed as internal IT helpdesk staff via phone calls and text messages, manufacturing urgency by claiming passkeys or multifactor authentication settings required immediate updates to prevent network lockout. Victims were directed to lookalike domains executing adversary-in-the-middle phishing and device-code authentication flows to bypass standard security controls. Once access was achieved, actors registered malicious authenticator applications to establish durable persistence. Microsoft Threat Intelligence attributed initial access operations to tracked groups including Storm-3121 and Storm-3032. Attackers utilized Microsoft Graph APIs to silently harvest emails and bulk exfiltrate files from SharePoint and OneDrive while staying below high-volume detection limits. Enterprise organizations face ongoing risks from out-of-band social engineering vectors exploiting trusted enterprise cloud management frameworks and legitimate administrative application programming interfaces.
By Ayesha A. | JQJO News
- Articles Published:
- 21
- Right Leaning:
- 0
- Left Leaning:
- 0
- Neutral:
- 21
- Distribution:
- Left 0%, Center 100%, Right 0%
Left: Highlighted corporate responsibility for securing cloud infrastructure against advanced social engineering. Center: Reported technical details and mitigations provided by Microsoft security telemetry. Right: Emphasized individual employee vigilance and private sector vulnerability to sophisticated attacks.
Microsoft Security Research disclosed enterprise mobile phishing campaigns on March 10 2026. https://www.microsoft.com/en-us/security/blog/
Coverage of Story:
From Left
No left-leaning sources found for this story.
From Center
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Dark Reading Huntress Blog Hard2bit Security PCMag VentureBeat Forbes Fast Company Engadget Gizmodo Reuters Bloomberg Wall Street Journal Financial Times Dark Reading Alternate Security Boulevard VentureBeat Alternate PCMag Alternate Gizmodo Alternate Engadget Alternate Fast Company Alternate Forbes AlternateFrom Right
No right-leaning sources found for this story.
Comments