Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
C darkreading ·
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key insight
Attackers use voice phishing on personal devices to gain Microsoft 365 access and then abuse the Graph API for large-scale data exfiltration, threatening conventional BYOD policies.
Description
Since May, Microsoft researchers have tracked at least two threat actor groups (Storm-3032 and Storm-3121) who call or send SMS messages to employees on their personal devices to manipulate them into authenticating to Microsoft 365. After successful compromise, attackers exploit the Microsoft Graph API to gain access to sensitive corporate data and extract it at scale. The exfiltrated data is then passed to extortion groups such as ShinyHunters. This attack chain demonstrates that seemingly low-risk access paths via personal devices are being systematically exploited by sophisticated actors.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 15.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational