Vishing crews ring personal phones to hijack Microsoft 365

Attackers posing as internal IT staff call and text employees on unmanaged personal phones, then quietly pull files from email, SharePoint and OneDrive.

MedRisk Staff
By
2 Min Read

Attackers are calling and texting employees on personal phones while posing as internal IT staff, then using the access to pull files and email from Microsoft 365 apps, SharePoint, OneDrive and inboxes for weeks at a time.

Microsoft Security Research has tracked the campaign since May 2026. Because the first contact lands on an unmanaged personal phone, investigators often have almost nothing to work with; in several reviewed cases the only lead was an employee recalling the call.

The caller manufactures urgency, saying a passkey, multifactor authentication or single sign-on setting must be updated immediately to avoid disruption. Victims are sent a link to a page dressed up as a Microsoft sign-in screen. Researchers note the passkey story is usually a pretext for adversary-in-the-middle phishing or device-code authentication flows rather than a genuine attempt to enroll credentials.

The attackers research targets first, mining professional networking sites for staff names and reporting lines. In some cases they reuse an already compromised account to pitch coworkers over Microsoft Teams, and they register lookalike domains carrying the victim organization’s name as a subdomain.

For healthcare organizations, where Microsoft 365 holds clinical correspondence and administrative PHI, the exposure is substantial. Security teams should move to phishing-resistant multi-factor authentication, restrict device-code flows, monitor for unusual mailbox access, and remind staff that IT will never call a personal phone to fix a passkey.

Share This Article