Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: graph-api (1 article)Clear

Voice phishing turns personal devices into a path to Microsoft 365 data

Researchers describe attackers using voice phishing calls to talk employees into granting access from their personal devices, then reaching Microsoft 365 and corporate data through the trust the user extends. The attackers do not hack the device; they convince the person, then use Microsoft's Graph API to identify valuable targets and pass access to extortion groups like ShinyHunters. Because the weakness is the user's decision rather than the hardware, banning personal devices would not stop it. The stronger defense is tightening identity and authentication and limiting what a compromised account can actually do, so that tricking one person yields far less to the attacker.

Check
Train staff to be suspicious of unsolicited support and IT calls that ask them to approve access or run steps, and verify such requests through a known internal channel before acting.
Affected
Organizations where employees can be socially engineered by phone into granting Microsoft 365 access from personal devices; attackers then use built-in cloud interfaces to find targets and hand access to extortion groups.
Fix
Enforce phishing-resistant authentication and conditional access, minimize standing privileges so a hijacked account does little, monitor Graph API and sign-in activity for abuse, and train users specifically against voice-based social engineering.