Story thread · 3 reports / 2 sources
Attackers are calling employees’ personal phones to break into Microsoft 365 accounts
helpnetsecurity.com · 4d
How the coverage leans
Across 2 sources · syndicated copies counted once
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research. (Source: Microsoft) Researchers have been tracking the campaign since May 2026. Because the initial contact often happens on a … More → The post Attackers are calling employees’ personal phones to break into Microsoft 365 accounts appeared first on Help Net Security .
First report: Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks — thehackernews.com, 7d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.