Microsoft says Storm-3032 and Storm-3121 have been calling and texting employees on personal phones since May 2026, and the access they steal now appears to be moving on to extortion crews such as ShinyHunters. The campaign targets Microsoft 365, SharePoint, OneDrive, and Microsoft Graph accounts rather than corporate endpoints first.
The lure is an IT pretext sent to a BYOD phone: the victim is pushed toward a fake Microsoft sign-in or device-code approval, or an adversary-in-the-middle flow that captures credentials and session tokens. Once inside, the operators can register their own MFA method and use Microsoft Graph to pull mail and files, which gives them a foothold that survives the victim’s next login challenge.
The lasting exposure sits in the identity layer, not the managed device. If your users approve work access from personal phones, the initial contact may leave little endpoint evidence while the account remains reusable, and any brokered access can outlive the original intrusion by being passed to the next crew.