Threat Actors Target BYOD Users with Calls and Texts to Phish Microsoft 365 Credentials

Summary
Threat actors impersonate IT help desks by calling and texting employees on personal devices, directing them to phishing pages designed to steal Microsoft 365 credentials and authentication tokens.
Key points
- Attackers contact employees on personal mobile devices by phone and text, posing as IT help desks.
- The messages direct targets to phishing pages designed to steal Microsoft 365 credentials and authentication tokens.
- The attackers target unmanaged BYOD devices, which may bypass some corporate security controls.
- Compromised identities can be used to access and exfiltrate data from SharePoint, OneDrive, and Exchange.
Article Details
- Event Type
- Voice and text phishing targeting employees on personal BYOD devices through IT help-desk impersonation.
- Impact
- Phishing pages are designed to steal Microsoft 365 credentials and authentication tokens. The source says compromised identities could enable access to and exfiltration of sensitive data from SharePoint, OneDrive, and Exchange; it does not confirm a specific data breach.
MITRE ATT&CK
Vendors
Products
Exchangeidentities to access and exfiltrate sensitive data from services including SharePoint, OneDrive, and Exchange.Microsoft 365mobile devices, impersonating IT help desks and directing them to phishing pages designed to steal Microsoft 365 credentials and authentication tokens.Microsoft SharePointcontrols and use compromised identities to access and exfiltrate sensitive data from services including SharePoint, OneDrive, and Exchange.OneDriveuse compromised identities to access and exfiltrate sensitive data from services including SharePoint, OneDrive, and Exchange.