ZeroHour
Dark Readingpublished ()ingested Nate Nelson
Part of a story covered by 13 sources: “Passkey-themed vishing by Storm-3121/Storm-3032, N0va phishkit, blob-URL phishing, and M365 Direct Send spoofing headline a week of identity attacks” — merged summary and timeline →

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

highThreat actor exploited in the wildimportance 70
AI summary · glm-5.3-flash

Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.

Dark Reading reports that threat actors are exploiting BYOD scenarios and voice-based social engineering to gain access to Microsoft 365 environments and corporate data. The actors use Microsoft's Graph API to identify lucrative targets within compromised tenants. Access is then passed to extortion groups such as ShinyHunters, which is known for large-scale data theft and extortion campaigns. The source text is a brief summary, so victim counts and full scope are not specified.

  • Voice-based social engineering in BYOD contexts used to reach Microsoft 365 corporate data
  • Microsoft Graph API leveraged to enumerate environments and identify lucrative targets
  • Access subsequently handed to extortion groups, including ShinyHunters
  • Organizations permitting BYOD face heightened exposure to voice-led account takeover
VendorsMicrosoft
Threat actorsShinyHunters
OrganizationsMicrosoft
Full article

Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.