SharePoint Data Theft Moves Through Identity Controls

SharePoint data can be stolen without breaking SharePoint at all. Helix is getting into Microsoft 365 tenants by abusing the people and processes around login approval, then reading whatever the compromised account can see. BleepingComputer says the group uses vishing, device-code phishing, and MFA abuse against SharePoint environments. That points to a cloud identity problem, not a patching problem, and it reaches Microsoft 365 data even when the platform itself is fully up to date. The risk sits in the trust path around MFA resets and approval prompts. If that path is weak, stolen credentials are not the only problem; a live session or approved login step can hand over access to the tenant's content layer.

Part of the PlainSec briefing for 2026-07-10

Editions

Sources