Threat actors are using employees’ personal phones as an entry point into Microsoft 365 environments, according to Microsoft Security Research. The attacks involve phone calls or text messages in which criminals pretend to be members of an organization’s IT helpdesk. Victims are told that they must update a passkey, multifactor authentication or single sign-on setting to avoid losing access to their work accounts. The attackers then send a link that leads the employee to a fake Microsoft sign-in page designed to steal credentials or authentication sessions.

Microsoft has been tracking this activity since May 2026 and has linked the initial access activity to threat actors including Storm-3032 and Storm-3121. The attackers mainly target personal devices because these devices may not have the same security monitoring and protections as company-managed systems. Microsoft said that in many investigations, an employee’s memory of a phone call or text message can become the earliest, and sometimes only, evidence showing how the compromise started. This makes these attacks difficult to investigate because much of the initial activity happens outside normal corporate security systems.

After gaining access to an employee’s identity, attackers can register their own authentication method to maintain access to the compromised account. They then use Microsoft Graph, a legitimate interface that provides access to Microsoft cloud services, to investigate the organization’s environment. Through Graph API activity, attackers can enumerate users, groups, applications, permissions, SharePoint sites, OneDrive resources and mailbox information. Individual Graph requests may look normal because organizations use the same API for legitimate business activity, but a large sequence of related requests can reveal suspicious reconnaissance.

The attackers can then move from reconnaissance to collecting corporate information stored in Microsoft 365. Microsoft observed activity involving SharePoint Online, OneDrive for Business and Exchange Online, including access to files, documents, emails and attachments. Instead of quickly downloading huge amounts of information, attackers often collect data gradually over hours or several days, helping the activity blend into normal cloud usage. Microsoft also observed automated activity and high-volume access patterns, including cases involving the python-httpx user agent, although the user agent alone should not be considered proof of malicious activity.

The stolen access may also be passed to extortion groups, including ShinyHunters, according to reporting on the campaign. Microsoft said Storm-3121 activity can lead to ShinyHunters and Falcon extortion, while Storm-3032 represents actors operating under the Helix extortion banner. The important point is that the attackers do not necessarily need to break into a company’s internal network directly. Instead, they abuse trusted identities, legitimate cloud services and employees’ personal devices to reach valuable corporate information.

Microsoft recommends treating unusual sign-ins, newly registered authentication methods, Microsoft Graph reconnaissance and abnormal cloud downloads as connected parts of the same attack. Organizations should use phishing-resistant MFA, require managed and compliant devices where appropriate, restrict unnecessary device-code authentication and closely monitor Graph, SharePoint, OneDrive and Exchange activity. Employees should also be trained to verify unexpected IT requests through trusted channels instead of following authentication links received during unsolicited calls or messages. The campaign shows that protecting Microsoft 365 requires controlling identity and access as carefully as protecting corporate devices themselves.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news