Tech News
← Home  ·  All topics

Microsoft Graph Api

1 GoKawiil brief on this topic

Hackers Target Personal Phones to Breach Microsoft 365 via BYOD Policies

Microsoft says threat groups Storm-3032 and Storm-3121 have been calling or texting employees on personal devices since May, posing as internal IT helpdesks to steal credentials and bypass corporate authentication protections. The attackers then abuse the Microsoft Graph API to exfiltrate corporate data at scale, and researchers believe they hand off this access to extortion gangs such as ShinyHunters. No specific breaches have yet been tied directly to these campaigns.