Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

Cyberattackers are exploiting a seemingly low-risk vulnerability in remote work settings to gain access to corporate data, including sensitive information stored on Microsoft 365 platforms. By targeting employees’ personal devices and using a combination of social engineering tactics and technical exploits, attackers are able to bypass companies’ security protections and extract valuable data.

The attacks, which have been tracked by Microsoft researchers since May, involve initial access brokers (IABs) calling or texting employees on their personal devices, often impersonating IT helpdesks. The pretexts for the calls vary, but typically involve a fake request for employees to update their authentication methods in order to maintain access to company resources.

Once an employee falls for the phishing attack and clicks on the malicious link, attackers are able to utilize adversary-in-the-middle (AiTM) techniques to steal credentials and session tokens. Device code phishing flows are also used to further compromise corporate systems.

What’s particularly concerning about these attacks is that they often occur outside of company-controlled systems. As Microsoft noted in its blog post, investigators frequently rely on employees’ recollections of phone calls or text messages as the earliest evidence of a breach. Reconstructing the attack from this point requires connecting various events, such as sign-ins, device code authentication, token activity, and changes to authentication methods.

The attackers have also demonstrated an ability to adapt their tactics, using malicious domains that combine victims’ employers with relevant security phrases. In some cases, compromised employee accounts are used to phish other employees, allowing attackers to establish persistent access by registering their own multifactor authentication (MFA) devices.

One of the most significant factors in these attacks is the use of the Microsoft Graph API, which allows attackers to perform large-scale corporate data exfiltration. This API enables them to enumerate and extract valuable information from company systems, making it a critical component of their extortion efforts.

The implications of this attack vector are far-reaching. As more companies adopt bring-your-own-device (BYOD) policies and remote work becomes increasingly common, the risk of these types of attacks will only continue to grow. It’s essential for employees to be aware of these tactics and take steps to protect themselves, including being cautious when receiving unsolicited calls or text messages from unknown numbers.

In practical terms, this means that companies should educate their employees about the risks associated with personal devices in the workplace. Phishing training programs can help employees recognize suspicious communication and avoid falling prey to these types of attacks. Additionally, implementing robust security measures, such as advanced threat detection and response systems, can help mitigate the impact of a potential breach.

Ultimately, the success of these attacks highlights the importance of balancing remote work flexibility with robust cybersecurity measures. By staying vigilant and adapting to emerging threats, companies can reduce the risk of these types of attacks and protect their sensitive data from falling into the wrong hands.


Source: Dark Reading — 2026-09-10