Back to Feed
Threat IntelligenceSep 10, 2026

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

Attackers use Graph API to find Microsoft 365 targets for extortion groups.

Summary

Threat actors are exploiting Bring Your Own Device (BYOD) policies to gain access to corporate Microsoft 365 environments. They leverage Microsoft's Graph API to identify high-value targets and then sell this access to extortion groups, such as ShinyHunters. This tactic bypasses traditional security measures by exploiting legitimate API access.

Indicators of Compromise

  • malware — ShinyHunters

Entities

BYOD (technology)Microsoft 365 (product)Graph API (technology)ShinyHunters (threat_actor)