Attackers call employees’ personal phones to break into Microsoft 365 accounts

Attackers call employees’ personal phones to break into Microsoft 365 accounts
Attackers are impersonating internal IT staff over calls and texts to trick employees into giving access to corporate Microsoft 365 accounts, then quietly stealing files and email through SharePoint, OneDrive, Exchange Online, and Microsoft Graph. Microsoft says the campaign relies on passkey and MFA pretexts, persistent account takeover methods, and low-and-slow data theft tied to threat actors such as Storm-3121 and Storm-3032. #Microsoft365 #SharePoint #OneDrive #ExchangeOnline #MicrosoftGraph #Storm3121 #Storm3032 #ShinyHunters #Falcon #BlackFile #Helix

Keypoints

  • Attackers call or text personal phones while posing as internal IT staff.
  • They use passkey, MFA, and SSO update lures to steal access credentials.
  • They browse public sources and reuse compromised accounts to target coworkers.
  • After entry, they add their own MFA methods to maintain durable persistence.
  • They use Microsoft Graph, SharePoint, OneDrive, and Exchange Online to quietly steal data.

Read More: https://www.helpnetsecurity.com/2026/09/10/microsoft-365-social-engineering-personal-phones/