Your Personal Phone Is Now the Corporate Perimeter — and Attackers Are Calling It Directly
The line between your personal phone and your employer's network has quietly disappeared, and criminals have noticed before most HR departments have. According to Dark Reading, threat actors are using voice calls to exploit bring-your-own-device (BYOD) setups as an entry point into Microsoft 365, then handing that access to extortion groups like ShinyHunters. The target isn't a server in a data center — it's the device in your pocket.
Bottom Line
THE BOTTOM LINE: This isn't a story about a flaw in Microsoft's code — it's a story about the collapsed boundary between personal and professional technology, and a criminal economy organized well enough to exploit it at scale. Companies that treated BYOD as a cost-saving convenience are discovering it's actually an unguarded border, and the people standing on that border are employees who were never trained, equipped, or told they were the perimeter.