Skip to content
Tech News
← Back to articles

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

Attackers are shifting from hardened corporate email and endpoints to employees' personal phones, using voice calls and texts that impersonate IT helpdesks to harvest credentials and bypass authentication controls. Microsoft says two initial access brokers have been running these campaigns since May and likely hand off access to extortion crews such as ShinyHunters. For enterprises, it shows that BYOD tolerance — even limited BYOD — is now a practical route into Microsoft 365 and large-scale data theft via the Graph API.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — Phishing-resistant hardware keys are the practical answer to voice and text phishing that harvests Microsoft 365 credentials and session tokens. The YubiKey 5 NFC supports FIDO2/WebAuthn and taps to phones over NFC, so it works even when employees sign in from personal devices.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Initial access brokers (IABs) are phishing employees by calling or texting their personal devices, then exploiting the Microsoft Graph API to perform large-scale corporate data exfiltration.

It's almost unavoidable that, in general corporate settings, employees will use personal devices to access company resources. Only the most careful government, research, and other high-value organizations ban it entirely, and most security-forward organizations allow it insofar as employees don't use personal devices to engage with sensitive resources. Even this reasonable latter policy is being tested, though, by attackers who know how to maximize seemingly low-risk attack paths.

Since May, Microsoft researchers have tracked at least two threat actors — Storm 3032 and Storm-3121, in its nomenclature — exploiting personal devices to totally bypass companies' authentication security protections. Worse: The two Storms are then likely passing on their earned access to extortion groups, including the nettlesome ShinyHunters. (Microsoft however did not connect any known corporate breaches to these initial access campaigns.)

Related:Identity-Based AI Attack Threatens Security of Enterprise Data

IABs Exploit Personal Devices

It's intuitive that if an attacker wants to gain access to a corporate system, they should target a corporate account or device connected to it. The problem is that, in doing so, they'll have to face whatever security measures that company has in place to stop them: email security gateways, endpoint detection and response (EDR), what have you.

It's arguably far easier, then, to target employees' personal devices. Those — particularly mobile phones — possess few or no security barriers. And anyone who's worked in an office knows that people use their mobile phones in and around their work environments all the time.

Recently, threat actors have been calling or texting employees on their own devices, impersonating their employers' IT helpdesks. The pretext of the call is that the employee has to update some means of authenticating to their work accounts — a passkey, multifactor authentication (MFA), or a single sign-on (SSO) configuration — in order to not lose access to their work. Through a link sent to their phones, employees can log into their accounts and restore order.

If an employee doesn't shrewdly identify that an important work communication shouldn't reach them this way, they'll likely follow the phishing link to a convincing Microsoft sign-in page. At this point, attackers have been utilizing both adversary-in-the-middle (AiTM) techniques to steal credentials and session tokens, and device code phishing flows.

Related:Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

... continue reading