Threat Actors Exploit BYOD to Exfiltrate Microsoft 365 Corporate Data
Phishing brokers target employees by calling or texting personal devices, then abusing the Microsoft Graph API for large-scale corporate data exfiltration. Since May, Microsoft researchers tracked at least two threat actors bypassing authentication protections via BYOD and links that impersonate IT helpdesks and lead to convincing Microsoft sign-in pages.