Sep 24, 2026

Voice Callers Exploit BYOD to Access Corporate Data

In a story recently reported by Dark Reading, threat actors are calling and texting employees on personal mobile devices, impersonating IT help desks and directing them to phishing pages designed to steal Microsoft 365 credentials and authentication tokens. By targeting unmanaged BYOD devices, attackers can bypass many corporate security controls and use compromised identities to access and exfiltrate sensitive data from services including SharePoint, OneDrive, and Exchange.

Read the story at Dark Reading here.