In a story recently reported by Dark Reading, threat actors are calling and texting employees on personal mobile devices, impersonating IT help desks and directing them to phishing pages designed to steal Microsoft 365 credentials and authentication tokens. By targeting unmanaged BYOD devices, attackers can bypass many corporate security controls and use compromised identities to access and exfiltrate sensitive data from services including SharePoint, OneDrive, and Exchange.
Read the story at Dark Reading here.
© 2026 Zimperium. All Rights Reserved. Privacy Settings Modern Slavery Act Statement