Threat IntelligenceSep 10, 2026
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Attackers use Graph API to find Microsoft 365 targets for extortion groups.
Summary
Threat actors are exploiting Bring Your Own Device (BYOD) policies to gain access to corporate Microsoft 365 environments. They leverage Microsoft's Graph API to identify high-value targets and then sell this access to extortion groups, such as ShinyHunters. This tactic bypasses traditional security measures by exploiting legitimate API access.
Indicators of Compromise
- malware — ShinyHunters
Entities
BYOD (technology)Microsoft 365 (product)Graph API (technology)ShinyHunters (threat_actor)