Attackers Use Personal Phones for Microsoft 365 Account Takeovers via Vishing
Cybercriminals are impersonating IT staff to trick employees into revealing Microsoft 365 credentials by calling their personal phones.

A new social engineering campaign is targeting Microsoft 365 accounts by leveraging vishing, or voice phishing, tactics. Threat actors are initiating contact with employees not through corporate channels, but by calling or texting their personal mobile phones. This approach bypasses many traditional security controls that focus on corporate email and network perimeters.
The attackers impersonate internal IT support or help desk personnel. Their goal is to gain the trust of the employee and convince them that a security issue requires immediate attention. This often involves requesting credentials, multi-factor authentication (MFA) codes, or directing the user to a fake login portal to "resolve" the fabricated problem.
Once an attacker successfully obtains credentials or MFA tokens, they can gain access to a victim's Microsoft 365 environment. This access allows them to exfiltrate sensitive data from various Microsoft 365 applications, including emails from Outlook, documents from SharePoint, and files stored in OneDrive. Microsoft Security Research has observed these actors maintaining access for extended periods, sometimes weeks.
This campaign, which Microsoft Security Research has been tracking since May 2026, highlights a shift in attacker methodologies. By targeting personal devices, threat actors exploit the blurred lines between personal and professional life, making it harder for employees to discern legitimate requests from malicious ones. The use of personal phones also circumvents security measures that might monitor or block suspicious activity on corporate-issued devices.
The impact of such attacks can be severe, leading to data breaches, intellectual property theft, and potential financial losses. The extended access period allows attackers to conduct thorough reconnaissance within the compromised environment, identify high-value targets, and potentially move laterally to other systems or cloud services.
Microsoft has been actively monitoring and responding to these evolving threats. While specific mitigation details for this particular vishing campaign are not extensively detailed in the initial reports, organizations are generally advised to reinforce security awareness training for employees, emphasizing the dangers of social engineering and the importance of verifying requests through established, out-of-band channels.
This tactic underscores the persistent innovation of cybercriminals in finding new vectors to compromise cloud services. As organizations increasingly rely on cloud platforms like Microsoft 365, attackers will continue to adapt their methods to exploit human vulnerabilities and bypass technical defenses, making ongoing vigilance and comprehensive security education critical.