Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Threat actors use voice calls and Microsoft Graph API via BYOD devices to access Microsoft 365, then sell access to extortion groups like ShinyHunters.
Dark Reading reports that threat actors are exploiting BYOD scenarios and voice-based social engineering to gain access to Microsoft 365 environments and corporate data. The actors use Microsoft's Graph API to identify lucrative targets within compromised tenants. Access is then passed to extortion groups such as ShinyHunters, which is known for large-scale data theft and extortion campaigns. The source text is a brief summary, so victim counts and full scope are not specified.