Executive Summary

Since May 2026, Microsoft researchers have tracked threat actors Storm-3032 and Storm-3121 conducting sophisticated initial access campaigns targeting corporate executives through their personal devices. The attackers use voice calls and text messages impersonating IT helpdesks to trick employees into updating authentication credentials via phishing links. Once access is gained, the threat actors exploit Microsoft Graph API to enumerate corporate resources and exfiltrate sensitive data from SharePoint, OneDrive, and Exchange before potentially selling access to extortion groups like ShinyHunters.

This campaign highlights the growing trend of attackers bypassing corporate security controls by targeting the weakest link - personal devices with minimal security protections. As organizations increasingly adopt BYOD policies and hybrid work models, identity-based attacks exploiting trusted communication channels represent a critical evolution in threat actor tactics.

Why This Matters Now

The rise of hybrid work and BYOD policies has created new attack vectors that bypass traditional corporate security controls, making identity-based social engineering campaigns increasingly effective and urgent to address.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations should implement phishing-resistant MFA, restrict device code authentication flows, and establish conditional access policies that limit corporate resource access to managed devices only.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this Microsoft 365 breach by limiting lateral movement across cloud workloads and reducing the attackers' ability to enumerate resources through segmented access controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero trust controls would likely have limited the scope of initial access by enforcing stricter identity verification and reducing the blast radius of compromised credentials through segmented authentication pathways.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Segmentation policies would likely have constrained privilege escalation by isolating administrative functions and reducing the reachability of high-privilege accounts across the Microsoft 365 environment.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained lateral movement by limiting communication paths between user accounts and reducing the attackers' ability to spread across the organization's cloud workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Enhanced visibility controls would likely have detected and constrained the extensive API enumeration activities, reducing the attackers' ability to map organizational resources and data repositories.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely have constrained data exfiltration by monitoring outbound data flows and reducing the volume of sensitive information that could be extracted through controlled egress policies.

Impact (Mitigations)

While some data exposure may have occurred, the overall impact would likely have been significantly reduced through limited access scope and constrained data reachability across the segmented environment.

Impact at a Glance

Affected Business Functions

  • Email and Communications (Exchange)
  • Document Management (SharePoint)
  • Cloud Storage (OneDrive)
  • Identity and Access Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Corporate data from SharePoint, OneDrive, and Exchange systems including potentially sensitive business documents, communications, and user credentials. Threat actors performed reconnaissance via Microsoft Graph API to identify high-value data targets before exfiltration.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies and least privilege access controls to limit Microsoft Graph API permissions and prevent broad reconnaissance capabilities
  • Deploy Multicloud Visibility & Control systems to detect anomalous Graph API usage patterns and repeated malformed requests that indicate reconnaissance activities
  • Enforce Egress Security & Policy Enforcement to monitor and restrict outbound data transfers from SharePoint, OneDrive, and Exchange to prevent gradual exfiltration
  • Establish Threat Detection & Anomaly Response capabilities to baseline normal Graph API usage and alert on suspicious batch calls or data access patterns
  • Require phishing-resistant MFA and restrict device code authentication flows while implementing conditional access policies that limit application access to managed devices only

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image