Threat actors are executing a social engineering campaign targeting employees on unmanaged personal phones to compromise Microsoft 365 cloud environments and extract sensitive enterprise data.
Tracked by researchers since May 2026, the ongoing attacks begin when threat actors contact corporate personnel via phone calls or text messages while posing as internal IT support. The operators establish urgency by claiming that multifactor authentication (MFA), single sign-on (SSO), or passkey configurations require immediate updates to prevent operational disruptions.
“The caller creates a sense of urgency, explaining that a passkey, multifactor authentication (MFA), or single sign-on (SSO) configuration must be updated immediately to avoid disruption,” researchers noted regarding the initial social engineering vectors. Victims are directed to malicious web domains that mimic standard Microsoft sign-in interfaces.
Rather than enrolling genuine passkeys, adversaries leverage these pretexts to execute adversary-in-the-middle (AiTM) phishing or device-code authentication flows. Attackers routinely harvest organizational intelligence from public sources and professional networking sites prior to launching attacks, occasionally hijacking previously compromised corporate identities to target coworkers over Microsoft Teams.
Once initial access is secured, intruders establish durable persistence by registering their own phone numbers, authenticator applications, or software-based one-time password tokens to bypass future authentication challenges. The operators subsequently leverage Microsoft Graph APIs to enumerate user accounts, administrative roles, and connected applications across targeted Microsoft 365 tenants.
“This attack serves as a strong example of why Graph activity must be assessed holistically, with emphasis on behavioral progression and cross-event correlation rather than individual API requests in isolation,” Microsoft explained.
Data exfiltration campaigns involve sustained, low-volume file downloads from SharePoint Online and OneDrive for Business, alongside email collection via Exchange Online REST APIs. By capping extraction rates below 1,000 files or emails per hour, the activity blends into standard enterprise traffic patterns while enabling long-term reconnaissance and data theft by groups such as Storm-3121 and Storm-3032.