Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Summary
Threat actors are exploiting Microsoft's Graph API to find targets and then handing off access to extortion groups. This allows attackers to gain access to Microsoft 365 and corporate data, often leveraging Bring Your Own Device (BYOD) scenarios.
IFF Assessment
FOE
This article describes a method used by threat actors to gain unauthorized access to corporate data and systems, posing a direct threat to defenders.
Defender Context
Defenders should be aware of the increasing sophistication of attacks leveraging cloud APIs like Microsoft Graph. It is crucial to implement strong access controls and monitoring for the Graph API, as well as to educate users on the risks associated with BYOD and suspicious voice calls.