Skip to content
Auto-CTI
Back to today
NEW Storm-3032, Storm-3121, ShinyHunters HIGH C3

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

C darkreading ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

Attackers use voice phishing on personal devices to gain Microsoft 365 access and then abuse the Graph API for large-scale data exfiltration, threatening conventional BYOD policies.

Description

Since May, Microsoft researchers have tracked at least two threat actor groups (Storm-3032 and Storm-3121) who call or send SMS messages to employees on their personal devices to manipulate them into authenticating to Microsoft 365. After successful compromise, attackers exploit the Microsoft Graph API to gain access to sensitive corporate data and extract it at scale. The exfiltrated data is then passed to extortion groups such as ShinyHunters. This attack chain demonstrates that seemingly low-risk access paths via personal devices are being systematically exploited by sophisticated actors.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC