Microsoft Tracks Two Threat Actors Exploiting Personal Devices to Breach Microsoft 365

This digest was compiled by AI from multiple sources — links to the originals are below.
Microsoft researchers have tracked two threat actors, Storm 3032 and Storm-3121, since May exploiting employees' personal devices to bypass corporate authentication protections and exfiltrate data from Microsoft 365. The attackers phish employees via calls or texts impersonating IT helpdesks, then use Microsoft Graph API for large-scale data theft. Microsoft has not connected any known corporate breaches to these initial access campaigns.
Key Facts
- Microsoft has tracked at least two threat actors, Storm 3032 and Storm-3121, since May exploiting personal devices to bypass corporate authentication protections.
- The attackers use phone calls or text messages impersonating IT helpdesks to phish employees, then exploit Microsoft Graph API for large-scale data exfiltration.
- Microsoft has not connected any known corporate breaches to these initial access campaigns.
- The threat actors are likely passing on their earned access to extortion groups, including ShinyHunters.
Attack Methodology
Threat actors call or text employees on their personal devices, impersonating their employers' IT helpdesks. The pretext is that the employee must update authentication methods such as passkeys, MFA, or SSO configurations to avoid losing access. Employees receive a link to a convincing Microsoft sign-in page, where attackers use adversary-in-the-middle techniques or device code phishing to steal credentials and session tokens. Microsoft notes that in many investigations, the employee's recollection of a phone call or text message becomes the earliest and sometimes only evidence of how the compromise began.
Exploitation of Personal Devices
Personal devices, particularly mobile phones, have few or no security barriers compared to corporate systems protected by email gateways and endpoint detection. Most organizations allow employees to use personal devices for work, though often with restrictions on accessing sensitive resources. The attackers exploit this by conducting nearly all phishing activity outside corporate systems, leaving minimal forensic traces.