Callers Impersonating IT Staff Compromise Corporate Cloud Access

Criminals are bypassing corporate security by targeting employees' personal mobile devices. By posing as internal IT support, they trick staff into approving fraudulent authentication requests, granting attackers long-term access to sensitive company data.
A new wave of cyberattacks is exploiting a blind spot in corporate security: the personal smartphones of employees. Attackers are calling or texting staff members directly on their private devices, pretending to be internal IT personnel. They create a sense of urgency, claiming that critical security settings like multifactor authentication need immediate updates to prevent system disruptions. This social engineering tactic bypasses managed company laptops and networks, leaving little digital trail for investigators to follow. As reported by GN technics/software (en-US), these campaigns have been active since May 2026 and are proving difficult to detect because the initial interaction happens outside the company's controlled environment.
The attackers do not simply ask for passwords. Instead, they guide victims through a convincing fake sign-in page that mimics Microsoft’s official interface. This is a technique known as an 'adversary-in-the-middle' phishing attack. The goal is not just to steal a password, but to capture a valid session token while the user is actively logged in. By using the victim’s own active session, the criminals bypass standard security checks. Once they have this access, they can immediately register their own authentication methods, such as a new phone number or authenticator app, under the compromised account. This ensures they can log in again in the future, even if the original session expires or the password is changed.
Attackers Prepare Extensive Reconnaissance
Before making contact, the attackers conduct thorough research. They gather information about the target organization’s structure, employee roles, and even specific project details from public sources like professional networking sites. This preparation allows them to craft convincing messages that reference real teams or projects, increasing the likelihood that employees will trust the request. In some cases, they reuse already compromised accounts to send these pitches to colleagues via Microsoft Teams. Seeing a message from a trusted coworker makes the request seem legitimate, reducing the victim’s suspicion. The attackers also register generic web domains that include the target company’s name as a subdomain. This makes the malicious links look familiar and official at a glance, further lowering the victim’s guard.
Stealthy Data Extraction Techniques
Once inside the system, the attackers move with caution. They use Microsoft Graph, a central application programming interface that connects various services like email, files, and user profiles. By making specific queries to this interface, they can map out who has what permissions and locate sensitive data. Security researchers note that this stage is hard to detect because individual requests look like normal business activity. The red flags only appear when an account accesses a wide variety of data categories in a short period. However, the attackers limit their activity to avoid triggering alerts. They cap their downloads at fewer than 1,000 files or emails per hour. This measured pace allows them to exfiltrate large amounts of data over days or weeks without standing out against the background noise of regular employee usage.
Challenges in Detecting Intrusions
The primary challenge for defenders is that the initial breach happens on a device the company does not control. Since the personal phone is not managed by corporate IT, it lacks the monitoring tools that track suspicious behavior. Often, the only evidence is the employee’s memory of the call. To combat this, organizations must train staff to be skeptical of urgent IT requests, especially those involving authentication changes. Additionally, security teams need to monitor for unusual patterns in API usage, looking for accounts that access diverse data types in rapid succession. Relying solely on individual event logs is insufficient; a holistic view of user behavior is necessary to spot these stealthy intrusions.






