Threat Actors Target BYOD Users with Calls and Texts to Phish Microsoft 365 Credentials

· Original article ↗

Summary

Threat actors impersonate IT help desks by calling and texting employees on personal devices, directing them to phishing pages designed to steal Microsoft 365 credentials and authentication tokens.

Key points

  • Attackers contact employees on personal mobile devices by phone and text, posing as IT help desks.
  • The messages direct targets to phishing pages designed to steal Microsoft 365 credentials and authentication tokens.
  • The attackers target unmanaged BYOD devices, which may bypass some corporate security controls.
  • Compromised identities can be used to access and exfiltrate data from SharePoint, OneDrive, and Exchange.

Article Details

Event Type
Voice and text phishing targeting employees on personal BYOD devices through IT help-desk impersonation.
Impact
Phishing pages are designed to steal Microsoft 365 credentials and authentication tokens. The source says compromised identities could enable access to and exfiltration of sensitive data from SharePoint, OneDrive, and Exchange; it does not confirm a specific data breach.

MITRE ATT&CK

Vendors

Products

Related Articles