Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
September 10, 2026
Initial access brokers (IABs) are phishing employees by calling or texting their personal devices, then exploiting the Microsoft Graph API to perform large-scale corporate data exfiltration.
It's almost unavoidable that, in general corporate settings, employees will use personal devices to access company resources. Only the most careful government, research, and other high-value organizations ban it entirely, and most security-forward organizations allow it insofar as employees don't use personal devices to engage with sensitive resources. Even this reasonable latter policy is being tested, though, by attackers who know how to maximize seemingly low-risk attack paths.
Since May, Microsoft researchers have tracked at least two threat actors — Storm 3032 and Storm-3121, in its nomenclature — exploiting personal devices to totally bypass companies' authentication security protections. Worse: The two Storms are then likely passing on their earned access to extortion groups, including the nettlesome ShinyHunters. (Microsoft however did not connect any known corporate breaches to these initial access campaigns.)







