Personal-phone scams open the door to Microsoft 365 data theft
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 11th, 2026.
Attackers are reaching corporate cloud data by calling or texting employees on their personal phones. They pose as internal IT staff and create urgency around a passkey, multifactor authentication, or single sign-on setting that supposedly needs to be updated. The victim is then directed into a phishing or device-code flow that can hand over a usable Microsoft 365 session. Once inside, the attacker may register a new phone number, authenticator application, or other authentication method to maintain access. The intruders use Microsoft Graph to map users, groups, permissions, files, and mail before collecting content from SharePoint, OneDrive, and Exchange. Some activity stays below one thousand files or emails per hour to blend with normal use. Because the first contact happens on a personal device, investigators may find little corporate evidence beyond the employee’s memory of the call or text. Leaders should treat personal-device use and helpdesk verification as identity-security issues. Defenders should correlate unusual sign-ins, new authentication methods, broad cloud discovery, and sustained downloads. Require phishing-resistant authentication and a verified internal process for every unexpected request to change sign-in settings.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.