Follow the latest coverage, related explainers and connected technology stories.
Microsoft Security Research observed a series of intrusions that begin with calls and messages impersonating IT support, then exploit AiTM or device code flows to add an attacker-controlled MFA method, explore Microsoft Graph, and extract SharePoint, OneDrive, and email data. Microsoft says the activity has been ongoing since May 2026 and aims to turn temporary identity compromise into persistent cloud access.