Personal Devices Compromised: Attackers Exploit BYOD for Corporate Data Exfiltration
Attackers are exploiting personal devices to bypass corporate security protections and gain access to sensitive data.
The attackers, tracked by Microsoft researchers as Storm 3032 and Storm-3121, use phishing tactics to trick employees into updating their work accounts on their personal devices. They then exploit the Microsoft Graph API to perform large-scale corporate data exfiltration.
The Graph API is a shared doorway for all Microsoft cloud services, allowing permissioned users to inventory users, resources, content, permissions, and other information useful for an attacker wanting a full lay of the land.
Microsoft researchers suggest that organizations should more actively log and hunt for suspicious application data exfiltration events and batch Graph API calls, and tightly restrict users' Graph permissions in general. They also recommend stricter authentication and authorization measures to limit the damage employees can do if they make a bad decision.