Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Attackers call employees pretending to be IT, trick them into giving up their Microsoft 365 login, then steal company files and demand ransom. Microsoft 365 users should watch for unexpected calls asking for credentials.
- Report priority
- High
- Victim
- Microsoft
What to do
Check your Microsoft 365 account for unusual activity, like files you didn't access or emails you didn't send. If you suspect your account was compromised, change your password immediately and report the call to your IT team.
Change your Microsoft 365 password right away if you gave your login to an unexpected caller. Report the incident to your company's IT department and ask them to check for signs of unauthorized access. Enable multi-factor authentication (MFA) on your Microsoft 365 account if it's not already turned. Your IT team can help with this.
Reported details
An attacker calls an employee at a company, pretending to be from IT support. The attacker says the employee's account is locked and needs verification. The employee, thinking it's real IT help, gives their Microsoft 365 username and password. The attacker then uses those credentials to access company files and data, stealing sensitive information before demanding a ransom.
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.